Project 4: System Development or Application Assurance Step 13: Write the Risk Analysis/Supply Chain Threats/Mitigation Report
Template for Project 4, Steps 2-6
|
Procurement Policy Concerns |
Specific Testing Recommendation to Address Each Policy Concern |
|
Does the vendor provide any cybersecurity certifications with the product? |
Inspect evidence provided by the vendor such as EAL certification or ISO certifications.
|
|
Does the vendor provide access to the source code for the product? Are there other security issues in source code to be addressed? |
|
|
What is the guaranteed frequency of security updates to be provided for the product? |
|
|
What is the implementation process for software updates/upgrades? |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|