Running_aa Head:_aa PROJECT_aa 4_aa 1
Project_aa 4_aa Step_a 13
PROJECT_aa 4 2
Overview
The_aa use_aa of_aa software_aa applications_aa in_aa the_aa Uber_aa organization_aa has_aa the_aa potential_aa to_aa give_aa rise_aa to_aa
risks_aa and_aa vulnerabilities_aa for_aa the_aa transport_aa and_aa mobility_aa business._aa An_aa in-depth_aa software_aa risk_aa analysis_aa
process_aa has_aa been _ carried_aa out_aa for_ the_a business_aa entity_aa so_aa that_aa it_aa will_aa be_ able _ to _aa identify _aa the _aa risks_aa
that_aa may_aa arise_aa within_aa the_aa supply_a chain _ network _a while _aa procuring_aa the_aa necessary_aa software_a applications_aa
such_aa as_aa operating_aa systems,_aa inventory_aa management_aa software,_aa office_aa suits_ and_aa communication_aa software_aa and_a
security_aa software_aa application._aa A_aa suitable_aa software_aa procurement_aa policy_aa list_aa has_aa been_aa developed_aa for_aa the_aa
Uber_aa organization_aa which_aa will_ enable_aa it_aa to_aa effectively_aa procure_aa necessary_aa software_aa applications_aa that_aa can_aa
aid_ in_aa conducting_aa the_aa business_ processes._aa The _aa report _aa also _aa sheds _aa light _aa on _aa appropriate_aa software_ acceptance _aa
procedures_aa along_aa with_aa testing_aa and_aa validation_aa procedures_aa that_aa can_aa be_a adopted_aa by_aa the_aa business_aa in_aa order_aa
to_aa ensure_aa compliance._aa The_aa major_aa supply_aa chain_aa cyber_aa security_aa risks_aa that_aa may_aa arise_aa before_aa the_aa business_aa
have_aa been_ identified _a and _aa an _aa acquisition_aa alignment_aa plan_ has_aa been_aa developed_aa that_ will_aa enable_ Uber_aa to_aa
ensure_aa that_aa all_aa the_aa functions_aa within_aa the_aa mobility_ business_aa operate_aa in_aa perfect_aa alignment.
The_aa report_aa has_aa been_aa developed_aa for_aa the_aa executive_aa team_aa at_aa Uber_a including_aa Maria_aa and_aa other_a
executives._aa The_aa information_aa that_aa has_aa been_aa incorporated_aa into_ the_aa report _aa will _aa broaden_aa their_aa insight_aa into _aa
potential_aa cyber_aa security_ implications_aa relating_aa to_aa procurement_aa and_a supply_aa chain_a risk_aa management_aa in_a the_aa
PROJECT_aa 4 3
context_aa of_aa software_aa applications._aa A_ number_aa of_aa software_aa risk_aa mitigation _ recommendations_aa have_aa been_
developed_aa that_aa will_aa enable_aa Uber_aa to_a manage_aa the_aa risks_aa and_aa optimally_aa procure_aa and_aa use_aa software_aa
applications_aa for_aa business_aa purposes._aa
Software_aa Vulnerability_aa Assessment
Application_aa Software_aa that_aa Could_aa Present_aa Vulnerabilities_aa
Operating_aa systems_aa such_aa as_ Windows_aa OS,_aa Linux,_aa iOS,_aa etc._aa –_aa The_aa operating_aa system_ that_aa is_ used_aa
within_aa the_aa organization_aa can_aa act_aa as_aa one_aa of_aa the_aa main_ software _aa components_aa that_aa can_aa increase_aa the_aa
vulnerability_aa and_aa threat_aa for_aa Uber._aa The_ existence_aa of_aa program_aa errors,_aa features_aa or_aa bugs_aa can_aa increase_aa the_aa
possibility_aa of_aa malicious_aa actors_aa to_aa violate_aa the _a software_aa and_aa compromise_aa the_aa software_aa assets_aa and_aa the_aa
IT_aa ecosystem_aa of_aa the_aa organization_aa (Yaacoub_aa et_aa al.,_ 2022).
Inventory_aa management_aa software_aa –_aa The _aa software _ will _aa enable _aa Uber _aa to_aa optimally_aa manage_aa its_aa inventory._aa
However,_aa if_aa the_a Integrated_aa Product_aa and_ Process_aa Development_aa (IPPD)_aa principles_aa are_aa not_aa integrated_aa while_
developing_aa the_aa software,_aa there_aa may_aa exist_aa security_aa gaps_aa that_a may_aa be_aa exploited_ by_aa cybercriminals._aa IPPD_aa
can_aa be_aa defined_aa as_aa a_aa management_aa process_aa that_aa starts_aa with_aa product_aa development_ and_aa goes_aa on_a through_aa
the_aa development_aa as_aa well_aa as_aa the_aa fielding_aa of_a the _a product_aa (Ayman_aa et_aa al.,_aa 2020)._aa The_aa software_aa must_aa
PROJECT_aa 4 4
be_aa aligned_aa with_aa the_aa specific_aa needs_a of_aa Uber_aa organization_a by_aa prioritizing_aa customer_aa focus,_ integrated_aa
management_aa tools,_aa early_aa and_aa continuous_aa life_a cycle_aa planning,_aa etc._ so_aa that_ software_aa –related_aa vulnerability_
can_aa be_aa curtailed._aa The_aa specific/customized_aa application_aa software_ that _aa the _aa Uber _ company _aa uses _aa is_aa a_aa
customer_aa support_aa automation_aa platform_aa which_aa enables_aa its_aa customers_aa to_aa reach_ out_aa to_aa the_aa business_aa to_aa
address_aa their_aa concerns.
Management_aa Information_aa System_aa (MIS)_aa or_aa other_aa similar_aa Information_aa System_aa (IS)_aa –_aa MIS_aa is_aa a_aa
vital_aa software_aa that_a collects_aa data_aa from_aa diverse_aa online_aa systems_aa and_aa evaluates_aa the_aa information_aa so_aa that_aa it_aa
can_aa assist_aa in_aa the_ decision-making_aa process._aa In_aa the_aa context_aa of_aa Uber_aa organization,_aa any_aa gap_aa in_a the_aa MIS_aa
application_aa can_aa increase_aa the_ vulnerability_aa of_aa the_aa business_aa and_aa compromise_a its_aa application_aa software_aa
processes._a Uber_aa should_aa strategically_aa engage_aa in_aa the_aa software_a development_aa process_aa while_aa developing_aa an_aa in-
house_aa MIS_aa software_aa or_aa buying_aa a_aa commercial_aa software_aa so_aa that_ software_aa security_aa can_aa be_aa prioritized._aa
Communication_aa software_aa such_aa as_aa Skype,_aa Zoom,_aa and_aa Google_aa mail_aa –_aa Every _aa organization_aa depends_aa
on_aa communication_aa and_ connectivity _aa tools _aa in _ order _aa to_aa ensure_aa that_aa it_aa is_aa possible_aa for_aa key_aa stakeholders_aa
to_aa have_aa a_a seamless_aa interaction_aa on_aa a_aa real-time_aa basis._aa However,_aa the_aa use_aa of_a communication_aa software_aa
without_aa appropriate_aa security_aa protocols_aa within_aa an_aa organization_aa can_aa give_aa rise_aa to_ vulnerabilities_aa and_aa threats_aa
in_aa the_aa cyber_aa setting_aa in_a the_aa form_aa of_ participation_aa of_aa malicious_aa actors_aa in_ team_aa interactions,_aa enabling_aa
PROJECT_aa 4 5
camera_aa without_aa the_aa knowledge_aa of_aa employees,_aa etc._aa (Arishina_aa et_aa al.,_aa 2022)._ In_aa order_aa to_aa minimize_aa the_aa
vulnerability,_aa it_aa is_aa imperative_aa for_a the_aa organization_aa to_aa make_aa use_aa of _a libraries_aa and_aa toolsets_aa to_aa test_aa
software_aa programs_aa before_aa their_aa implementation_aa or_aa use._aa
Security_aa software_aa applications_aa –_aa Although _aa security _aa applications _aa serve _aa as _aa a _aa vital _aa security _aa instrument _aa
for_aa organizations,_aa they_aa also_aa have_aa the_aa potential_aa to_aa give_aa rise_aa to_ vulnerabilities_aa and_aa threats.The_aa use_aa of_aa
obsolete_aa security_ applications _aa that _aa are _aa not _aa updated _aa on _aa a _a regular _aa basis _aa can _aa act _aa as _aa a _aa major _aa security _aa
gap_aa that_aa can_aa create_aa an_aa opportunity_aa for_aa malicious_aa actors_aa in_aa the_a cyber_aa setting_aa to_aa gain_aa unauthorized_aa
access_aa into_aa the_a IT_aa ecosystem_aa of_aa Uber._aa Similarly,_aa in_aa case_aa a_aa thorough_aa audit_aa of_aa the_ security_aa
applications_aa is_aa not_a conducted,_aa it_ might_aa not_aa be_a possible_aa to_ conduct_aa proper_aa patching_aa which_aa can_aa
increase_aa the_aa risks_aa and_aa vulnerabilities_aa for_aa the_ organization_aa in_aa the_ unpredictable_aa and_aa dynamic_aa cyber_aa
setting_aa (Dissanayake_aa et_aa al._aa 2022)._ It_ is_aa instrumental_aa for _a the_aa mobility_ and_aa transport_ organization_aa to_aa
use_aa maturity_aa models_aa to_aa ensure_aa that_a a_aa robust_aa software_aa security_aa strategy_aa is_aa introduced_aa and_aa deployed_aa
within_aa the_aa organization._aa For_aa example,_aa Uber_aa can_aa use_aa the_aa Capability_aa Maturity_aa Model_aa (CMM)_aa to_a make_aa
sure_aa that_aa optimum_aa capability_aa will_aa be_ possible _ while_a working_aa on_aa a_ secure_aa software_aa for _aa the _aa
organization_aa (Mohammed_aa &_aa Bade,_aa 2019)._aa
Office_aa suites_aa –_aa The_aa use_aa of_a office_aa suites_aa such_a as_aa Microsoft_aa Office,_aa or_aa Google_aa Workspace_aa may_aa
PROJECT_aa 4 6
contain_aa vulnerabilities_aa that_aa may_aa get_aa exploited_ by_aa cybercriminals_ or_aa online_ attackers._aa For_aa example,_
security_aa loopholes_aa and_ flaws_aa may_aa allow_aa attackers_aa to_aa take_aa control_aa of_aa the_a system_aa of_a the_aa Uber_aa
organization_aa and_aa gain_aa unauthorized_aa access_aa to_ sensitive_aa and_aa confidential_ business_aa data._aa aa_aa
Procurement_aa Policy_aa List_aa and_aa Acceptance_aa Procedures
Procurement_aa Policy_aa List_aa
Test_aa Script_aa Procedures_aa for_aa Software_aa Acceptance
One_aa of_a the_aa fundamental_aa procurement_aa policies_aa
that_aa must_aa be_aa introduced_aa in_aa Uber_aa company_aa is_aa
related_aa to_aa the_aa availability_aa of_aa cyber_aa security_aa
certifications_aa by_aa vendors_aa and_aa suppliers_aa of_aa
software_aa applications._aa The_aa policy_aa will_ enable_aa
Uber_aa to_aa choose_ vendors_aa who_aa prioritize_aa security_aa
in_aa the_aa dynamic_ and_aa unpredictable _ cyber_aa
domain._aa
The_aa cyber_aa security_a certifications_aa that_aa the_a vendor_aa
of_aa Uber_aa holds_aa will_aa serve_aa as_aa a_a vital_aa indication_aa
of_aa its_aa cyber_aa security_aa strength_a and_aa resilience._aa
Some_aa of_aa the_aa key_aa certifications_aa that_aa the_aa
transportation_aa company_aa must_aa look_aa for_aa in_aa order_aa to_a
get_aa assurance_aa are_aa ISO/_aa IEC_aa 27001,_aa SOC_aa 2,_aa etc.
ISO/_aa IEC_aa 27001_aa is_aa an_aa important_aa certification_aa
since_aa it_aa promotes_aa an_ integrated_aa and_aa comprehensive_aa
approach_aa to_aa information_aa security_aa (ISO,_aa n.d.)._aa Uber_a
must_aa lay_aa emphasis_aa on_ the_aa international_a standard_aa
PROJECT_aa 4 7
while_aa assessing_aa the_aa security_aa capabilities_aa of_aa the_
vendor._aa SOC_a 2_ is_aa also_ a_aa vital_aa auditing_aa
procedure_aa that_aa ensures_ that_aa the_aa service_ provider_aa
securely_aa handles_aa the_ data_aa of_aa its_aa client_aa to_aa
safeguard_aa its_aa interests.
Another_aa policy_aa that_a Uber_aa must_aa take_a into_aa
consideration_aa is_aa whether_aa the_aa vendors_aa of_aa the_aa
software_aa provide_aa access_aa to_aa the_aa mobility _
company_aa to_aa the_ source_aa code_aa of_aa the_aa software_aa
products._aa The_aa policy_ is_aa instrumental_aa to_aa identify_aa
and_aa assess_aa whether_aa there_aa exist_aa any_ security_aa
issues_aa at_aa the_aa source_aa code_aa level_aa or_ not._aa A_aa
broad_aa range_aa of_aa factors_aa may_aa come_aa into_ play_aa
and_aa contribute_aa to_ the_aa emergence_aa of_a security_aa
concerns_aa in_aa source_aa code,_aa such_aa as_aa the_aa integrity_aa
of_aa the_aa process,_aa and_aa the_aa development_aa
The_aa security_a team_aa of_aa the_aa vendor_aa must_aa engage_aa
in_aa a_aa session_a with_aa the_aa IT_aa team_aa of_aa Uber_aa
explaining_aa the_aa security_ controls_aa that_aa were_aa adopted_aa
during_aa the_aa source_aa code_aa development_aa process._aa For_aa
example,_aa it_aa can_aa explain_ how_aa techniques_aa such_aa as_aa
sandboxing,_aa isolation_aa of_aa the_aa source_aa code _
environment_aa or_aa password_aa protection_aa techniques_aa were_aa
adopted_aa by_aa it_a to_aa strengthen_aa the_aa security_aa at_aa the_aa
source_aa code_aa stage.
PROJECT_aa 4 8
environment._aa Since_aa source_aa code_aa is_aa susceptive_ to_aa
diverse_aa threats_aa and_aa uncertainties,_aa the_aa policy_aa
must_aa prioritize_aa the_a strength_aa of_aa the_aa source_aa code_aa
of_aa software._aa
The_aa guaranteed_aa frequency_aa pertaining_a to_aa software_aa
updates_aa should_aa be_aa integrated_aa into_aa the_aa
procurement_aa policy_aa of_aa Uber._aa This_aa policy-based_aa
measure_aa is_aa instrumental_aa since_aa it_aa will_aa enable_aa
the_aa Uber_aa organization_aa to_aa procure_aa software_aa
applications_aa that_aa can_aa be_a modified_aa and_aa updated_aa
flexibly_aa in_aa the_aa evolving_aa technological_aa landscape_aa
(Gonzalez_aa et_aa al.,_aa 2020)._aa
While_aa entering_aa into_a a_aa contract,_aa the_aa selected_aa
vendor_aa must_aa commit_aa the_aa minimum_aa number_aa of_aa
times_aa it_aa will_aa be_aa conducted_aa software_a updates _aa on _aa
an_aa annual_aa basis._aa Moreover,_aa it_aa must_aa also_aa clearly_aa
specify_aa the_aa exact_aa changes_aa that_aa will_aa take_aa place_aa
in_aa the_aa software_aa once_aa an_aa update_aa has_aa been_aa made._aa
Such_aa an_aa approach_aa is_aa essential_aa so_ that_aa Uber_aa will_aa
have_aa a_aa better_aa insight_aa and_aa understanding_aa of _ how_aa
the_aa software_aa application_ is_aa used_a within_aa the_aa
organization._aa
A_aa vital_aa procurement_aa policy_aa revolves_aa around_aa the_aa
need_aa for_aa additional_aa security_aa training_aa by_ the_aa
The_aa available_aa training_aa and_aa development_aa options_
that_aa are_aa available_aa with_aa the_aa selected_aa vendor_aa must_aa
PROJECT_aa 4 9
staff_aa members_aa of_aa Uber_aa organization_aa so_aa that_a
they_aa will_aa be_a able_aa to_aa implement_aa and_aa utilize_aa
the_aa newly_aa procured_aa software_aa applications_aa without_aa
any_aa hindrance_aa or_aa complexities._aa
be_aa thoroughly_aa assessed_aa to_aa ensure_a that_aa they_aa are_a
aligned_aa with_aa the_aa latest_aa industry_aa standards_ and_aa
requirements._aa The_aa eligibility_aa criteria_aa of_aa the_aa training_aa
professionals_a and_aa staff_aa must_aa be_aa examined_aa to_aa
ensure_aa they_aa are_aa qualified_aa to_ extend_aa training_aa
assistance_aa and_aa support_aa to_aa the_aa organizational_aa staff_aa
of_aa Uber_aa to_a use_aa the_aa new_a software_aa application._aa
The_aa policy_aa must_aa focus_aa on_aa the_aa ability_aa of_aa the_aa
software_aa sellers_aa of_aa Uber_aa to_aa regularly_ update _aa
the_aa security_aa framework_aa of_aa their_aa software_aa
solutions_aa so_aa that_a the_aa possibility_aa of_aa bugs,_aa
program_aa errors_aa and_aa other_aa kinds_aa of_aa
vulnerabilities_aa can_aa be_aa reduced._aa
The_aa software_aa must_aa be_aa monitored_aa on_aa a_aa regular_aa
basis_aa to_aa identify_aa gaps_aa or_aa vulnerabilities_aa that_aa may_aa
be_aa exploited_aa by_a malicious_aa actors_aa such_aa as_aa
cybercriminals._aa A_aa risk_aa assessment_aa expert_ must_a be_aa
appointed_aa by_aa the_aa organization_aa for_aa conducting_aa the_aa
monitoring_aa activity_aa at_aa a_aa holistic_aa level.
While_aa selecting_aa the_aa suppliers_aa before_aa making_aa the_aa
purchase_aa of_aa a_aa software_aa application_aa for_aa carrying_aa
out_aa the_aa business_aa operations,_aa it_a is_aa instrumental_aa
A_aa rigorous_aa software_ audit_aa and_aa testing_aa must_aa be_aa
conducted_aa by_aa Uber_aa organization_aa to_aa ensure_aa that_aa
the_aa selected_aa software_aa provider_aa complies_aa with_aa
PROJECT_aa 4 10
for_aa Uber_aa to_ critically_aa evaluate_aa them_aa to_aa ensure_a
how_aa well_aa they_aa adhere_aa to_aa the_ ever-changing_aa
industry_aa standards_aa relating_aa to_aa cyber_aa security._aa
By_aa integrating_aa this_aa important_aa dimension_aa into_aa
the_aa software_aa procurement_ policy,_aa Uber_aa can_aa
effectively_aa examine_aa the_aa capabilities_ and_aa
competencies_aa of_aa the_ potential_aa vendors_aa before_aa
making_aa the_aa final_aa selection._aa
appropriate_aa industry_aa standards_aa and_aa guidelines_aa
(Slapničar_aa et_aa al.,_aa 2022)._aa The_aa audit_aa process_aa will_aa
enable_aa the_aa mobility_a business_aa entity_aa to_ cross_aa
examine_aa the_aa software-related_aa capabilities_aa of_ the_aa
vendor._aa
A_aa mandatory_aa procurement_aa policy_ that_aa must_aa be_aa
adopted_aa by_aa Uber_aa is_aa that_aa it_aa must_aa engage_aa in_aa
a_aa well-planned_aa and_aa comprehensive_aa software_aa
development_aa process_aa (Saeed_aa et_aa al.,_a 2019)_aa with_aa
its_aa software_a vendor,_aa irrespective_aa of_aa whether_aa it_aa
decides_aa to_aa purchase_aa an_aa off-the-shelf_aa software_
solution_aa or_aa develop_a a_aa custom,_aa in-house_
software_aa application._aa The_aa Rapid_aa Application_aa
A_aa software_aa quality_aa assurance_aa is_aa a_a vital_aa process_aa
that_aa must_aa be_aa carried_aa out_aa to_ assure_aa the_a quality_aa
of_aa the_aa software_aa applications_aa that_aa are_aa being_aa
procured_aa by_aa Uber_aa from_aa its_aa vendors._ This_aa process_aa
fundamentally_aa involves_aa a_aa diverse_ range_aa of_aa
activities_aa like_aa test_aa planning,_aa performance_aa testing,_a
regression_aa testing,_aa usability_a testing_aa and_aa security_aa
testing_aa (Goericke,_aa 2020)_aa that_a will _aa enable _ that _aa the _aa
PROJECT_aa 4 11
Development_aa (RAD)_aa model_aa or_ Joint_aa Application_aa
Development_aa (JAD)_aa model_aa can_aa be_aa implemented_aa
in_aa the_aa organizational_aa context._aa For_aa example,_aa the_aa
adoption_aa of_ the_aa JAD_aa model_a will_aa enable_aa Uber_a
to_aa ensure_aa that_a diverse_aa techniques_aa such_ as_aa
workshops,_aa meetings,_aa etc._aa and_a carried_aa out_aa for_a
the_aa purpose_aa of_aa defining_aa as_aa well_aa as_aa designing_aa
the_aa software_aa system._aa
new_aa software_aa that_aa is_aa introduced_ in_aa the_ company_aa
can_aa serve_aa the_aa intended_aa purpose._aa
Another_aa vital_aa procurement_ policy_aa is_aa that_aa the_aa
vendor_aa must_aa honestly_aa and_a sincerely_aa communicate_aa
with_aa Uber_aa about_aa any_aa known_aa security_aa
vulnerabilities_aa or_aa loopholes_aa that_aa may_aa act_aa as _ a_aa
serious_aa threat_aa for_aa the_aa business._aa It_aa must_aa not_aa
try_aa to_aa deceive_aa the_aa mobility_ business_aa or_aa share_aa
inaccurate_aa information_aa relating_aa to_aa its_aa software_aa
applications_aa to_aa misguide_aa or_aa cheat_aa the_a business_aa
The_aa contract_a must_aa be_aa thoroughly_a reviewed_aa by_aa the_aa
security_aa team_aa of_aa Uber_aa to_aa check_aa that_aa the_aa vendor_
carries_aa out_aa its_aa duties_aa and_aa responsibilities_a in_aa a_
transparent,_aa sincere,_aa and_aa responsible_ manner._aa
Moreover,_aa the_aa members_aa involved_aa in_aa the_aa signing_aa
of_aa the_aa contract_aa must_aa openly_aa discuss_a the_aa
requirement_ to_ ensure_aa that_aa there_ is_aa utmost_aa clarity_
and_aa no_aa ambiguity_aa between_aa Uber_aa and_aa the_aa vendor_aa
PROJECT_aa 4 12
in_aa any_aa manner._aa The_aa role_aa of_aa transparent_aa and_
real-time_aa communication_ between_aa the_aa vendor_aa and_aa
the_aa transport_aa business_aa entity_aa is_aa of_aa cardinal_aa
importance_aa to_aa make_ sure_aa that_a both_aa can_aa work_aa
together_aa in_aa case_ any_aa gaps_aa arise_a in_aa the_aa
software_aa after_aa the_aa purchases_aa so_aa that_aa the_ issue_aa
can_aa be_aa effectively_aa resolved_aa (Hashim_ et_aa al.,_aa
2022)._aa
regarding_aa the_aa communication_aa process._aa
The_aa vendor_aa must_aa possess_aa documentation_aa that_aa
proves_aa that_aa the_aa software _ that _aa it _aa has _aa developed_aa
has_aa been_aa monitored_a throughout_aa the_aa development_aa
lifecycle_aa process._aa This_aa proof_aa must_aa be_ presented_aa
to_aa Uber_aa to_aa ensure_aa that_aa it_aa meets_aa the_a
necessary_aa security_aa requirements_aa of_aa the_aa
organization._aa
The_aa necessary_aa documentation_aa must_aa be_aa shared_aa with_aa
the_aa security_aa team_a of_ Uber_aa so_a that_aa they_aa can_aa
conduct_aa a_aa thorough_aa review_aa of_aa the_aa same_aa and_aa
ensure_a that_aa the_aa client_aa adheres_aa to_aa all_a the_aa
essential_aa security_aa requirements_aa of_aa Uber._aa Accurate_aa
documentation_aa must_aa be_aa shared_aa so_aa that_ a_aa thorough_aa
check_aa can_aa be_aa done_aa which_aa will_aa help_aa to_ get_aa a_
true_aa picture_aa of_aa the_aa strength_aa of_ the_aa security_aa
PROJECT_aa 4 13
dimensions_aa of_aa the_aa software_ application_aa of_aa the_aa
vendor.
Testing_aa and_aa Validation_aa Procedure
Procurement_aa Policy_aa Concern
Specific_aa Testing_aa Recommendation_aa to_aa Address_aa
Each_aa Policy_aa Concern
One_aa of_aa the_aa fundamental_aa procurement_aa policies_aa that_aa
must_aa be_aa introduced_aa in_aa Uber_aa company_ is_aa related_aa
to_aa the_aa availability_aa of_ cyber_aa security_a certifications_aa
by_aa vendors_aa and_aa suppliers_aa of_aa software_aa applications._aa
The_aa policy_aa will_a enable_aa Uber_aa to_aa choose_aa vendors_aa
who_aa prioritize_aa security_aa in_aa the_aa dynamic_ and_aa
unpredictable_aa cyber_aa domain._aa
A_aa vital_aa testing_aa activity_aa that_aa must_aa be_ carried_aa out_aa
by_aa Uber_aa while_aa procuring_ software_aa is_aa related_aa to_aa
a_aa thorough_aa and_aa in-depth_aa evaluation_aa of_a the _aa
vendors._aa While_aa evaluating_aa them_aa it_aa is_aa essential_aa to_
take_aa into_aa consideration_aa not_aa only_aa the_aa certifications_aa
that_aa they_aa hold_aa but_aa also_aa the_aa track_aa record,_aa the_aa
customer_aa base,_aa the_aa testimonials_aa of_aa the_aa customers_aa
and_aa reputation._aa Its_aa past_aa history_aa must_aa be_aa carefully_aa
examined_aa to_aa make_ sure _aa that _ it _aa adheres _aa to _
appropriate_aa industry_aa standards_aa while_aa delivering_aa
PROJECT_aa 4 14
software_aa solutions_aa to_aa its_aa clients._aa
Another_aa policy_aa that_a Uber_aa must_aa take_a into_aa
consideration_aa is_aa whether_aa the_aa vendors_aa of_aa the_aa
software_aa provide_aa access_aa to_aa the_aa mobility_aa company_aa
to_aa the_aa source_aa code_aa of_aa the_aa software_aa products._aa The_aa
policy_aa is_aa instrumental_aa to_aa identify_ and_aa assess_aa
whether_aa there_aa exist_aa any_aa security_aa issues_aa at_aa the_aa
source_aa code_aa level_a or_ not._aa A_aa broad_aa range_aa of_aa
factors_aa may_aa come_aa into_aa play_aa and_aa contribute_aa to_a
the_aa emergence_aa of _aa security_aa concerns_aa in_aa source_aa
code,_a such_aa as_aa the_aa integrity_aa of_aa the_aa process,_aa and_a
the_aa development_aa environment._aa Since_aa source_aa code_aa is_aa
susceptive_aa to_aa diverse_aa threats_aa and_aa uncertainties,_aa the_aa
policy_aa must_aa prioritize_aa the_aa strength_aa of_aa the_aa source_a
code_aa of_aa software._aa
It_ is_aa essential_aa to_aa lay_aa emphasis_aa on_aa the_aa software_
environment_ of_aa the_aa vendor_aa since_ it_aa can_aa have_aa a_
direct_aa implication_aa on_a the_aa security_aa features_aa of_aa the_aa
software_aa application_aa that_aa has_aa been_aa developed._aa
Some_aa of_aa the_aa key_aa elements_aa that_a must_aa be_aa taken_aa
into_aa account_aa while_aa evaluating_aa the_aa rigor_aa and_aa
strength_aa of_aa the_aa software _aa environment_aa of_aa the_aa
vendor_aa include_aa the_aa language,_aa processes,_aa security_aa
features_aa as_aa well_aa as_aa development_aa models._aa aa_aa _aa
The_aa guaranteed_aa frequency_aa pertaining_a to_aa software_aa
A_aa well-defined_aa change_aa management_aa procedure_aa
PROJECT_aa 4 15
updates_aa should_aa be_aa integrated_aa into_aa the_aa procurement_aa
policy_aa of_aa Uber._a This_aa policy-based_aa measure_aa is_
instrumental_aa since_aa it_aa will_aa enable_aa the_a Uber_aa
organization_aa to_aa procure_aa software_aa applications_aa that_
can_aa be_aa modified_aa and_aa updated_aa flexibly_aa in_aa the_aa
evolving_aa technological_aa landscape_aa (Gonzalez_aa et_aa al.,_aa
2020)._aa
should_aa be_aa in_a place_aa that_a will_aa help_aa to_ streamline_aa
the_aa updating_aa process_aa and_a other_aa kinds_aa of _ changes_aa
in_aa the_aa original_aa software. _aa The_aa procure_aa must_a also_aa
focus_aa on_aa other_aa areas_aa such_aa as_aa patch_aa management_aa
which_aa may_aa bring_aa about_aa a_aa change_aa in_aa the_aa
software_aa can_aa impact_aa the_aa mobility_aa business’_ ability_aa
to_aa use_aa the_ software_aa application_aa in_ the_aa business_aa
context._aa
A_aa vital_aa procurement_aa policy_aa revolves_aa around_aa the_aa
need_aa for_aa additional_aa security_aa training_aa by_ the_aa staff_aa
members_aa of_aa Uber_aa organization_aa so_aa that_aa they_aa will_aa
be_aa able_aa to_a implement_aa and_a utilize_aa the_aa newly_aa
procured_aa software_aa applications_aa without_aa any_aa hindrance_aa
or_aa complexities._aa
A_aa usability_aa testing_aa of_aa procured _a software_aa must_aa be_
carried_aa out_aa by_aa Uber_aa company._aa Such_aa a_aa testing_aa is_aa
instrumental_aa since_aa it_aa will_aa help_aa to_aa determine_aa
whether_aa the_aa software_aa that_ has_aa been_aa developed_aa
and_aa procured_aa can_aa be_aa easily_aa and_aa conveniently_aa
used_aa by_aa the_aa users_aa or_aa not_aa (Sasmito_a &_aa Nishom,_aa
2019).
The_ policy_a must_aa focus_aa on_a the_aa ability_aa of_aa the_
A_aa rigorous_aa security_aa testing_ must_aa be_aa carried_aa out_aa
PROJECT_aa 4 16
software_aa sellers_aa of_aa Uber_aa to_aa regularly_aa update_aa the_aa
security_aa framework_aa of_aa their_aa software_aa solutions_a so_aa
that_aa the_aa possibility_aa of_aa bugs,_aa program_aa errors_aa and_aa
other_aa kinds_aa of_aa vulnerabilities_aa can_aa be_aa reduced._aa
by_aa the_aa security_aa team_aa at_aa Uber_aa to_aa check_aa the_
effectiveness_aa of_aa the_a software’s_aa security_aa framework._aa
While_aa conducting_aa this_aa testing_aa activity,_aa it_aa is_aa
essential_aa to_aa make_aa sure_aa that_aa the_aa vendor_aa complies_aa
with_aa applicable_aa security_a standard_aa (Spillner_aa &_a Linz,_aa
2021)._aa
While_a selecting_aa the_aa suppliers_aa before_aa making_aa the_aa
purchase_aa of_aa a_aa software_aa application_aa for_aa carrying_aa
out_aa the_aa business_aa operations,_aa it_aa is_aa instrumental_aa for_aa
Uber_aa to_aa critically_a evaluate_aa them_aa to_aa ensure_aa how_aa
well_aa they_aa adhere_aa to_aa the_aa ever-changing_aa industry_aa
standards_aa relating_aa to_ cyber_aa security._ By_aa integrating _
this_aa important_aa dimension_aa into_ the_aa software_aa
procurement_aa policy,_aa Uber_aa can_aa effectively_aa examine_aa
the_aa capabilities_aa and_aa competencies_aa of_aa the_aa potential_a
vendors_aa before_aa making_ the_aa final_aa selection._
A_aa thorough_aa acceptance_aa testing_ must_aa be_aa carried_aa
out_aa by_aa Uber_aa company_aa since_aa it_a will_aa help_aa it_aa to_aa
ascertain_aa whether_aa the_ software_aa solution_aa of_aa the_aa
vendor_aa will_aa be_aa able_aa to_aa meet_ the_aa specific_aa
requirements_aa of_aa the_a transport_aa company_aa or_aa not._aa
While_aa carrying_aa out_aa the_aa acceptance_aa testing,_aa it_aa is_aa
instrumental_aa to_aa prioritize_aa the_aa security_a aspect_aa since_aa
it_aa will_aa serve_a as_aa the_aa backbone _a of_aa the_aa software_aa
and_aa influence_aa its_aa functionality_aa and_aa performance_aa
(Mohialden_aa et_aa al.,_aa 2022)._aa Furthermore,_aa it_aa is_aa
PROJECT_aa 4 17
essential_aa to_aa take_aa into_aa consideration,_aa the_aa industry-
based_aa standards_aa and_ requirements_aa while_aa performing_aa
the_aa testing_aa activities._
A_aa mandatory_aa procurement_aa policy_ that_aa must_aa be_aa
adopted_aa by_aa Uber_aa is_aa that _ it_aa must_a engage_aa in_a a_aa
well-planned_aa and_aa comprehensive_aa software_aa development_aa
process_aa (Saeed_aa et_aa al.,_ 2019)_aa with_aa its_aa software_aa
vendor,_aa irrespective_aa of_aa whether_a it_aa decides_aa to_aa
purchase_aa an_aa off-the-shelf_aa software_aa solution_aa or_a
develop_aa a_aa custom,_aa in-house_aa software_ application._aa
The_aa Rapid_aa Application_aa Development_aa (RAD)_aa model_
or_aa Joint_aa Application_ Development_aa (JAD)_aa model_aa can_aa
be_aa implemented_aa in_ the_aa organizational_aa context._aa For_aa
example,_aa the_aa adoption_aa of_aa the_aa JAD_aa model_aa will_aa
enable_aa Uber_aa to_ ensure_aa that_aa diverse_aa techniques_aa
such_aa as_aa workshops,_aa meetings,_aa etc._ and_aa carried_aa out_aa
A_aa documentation_aa review_aa must_ be_aa performed_aa by_aa
Uber._aa Such_aa an_aa activity_a is_aa vital_a since_aa it_aa will_aa
enable_aa the_aa mobility_a business_aa to_aa ensure_ that_aa the_aa
chosen_aa vendor_aa adopts_aa a_aa systematic_aa and_ thorough_aa
process_aa throughout_aa the_aa software_aa development _
process._aa
PROJECT_aa 4 18
for_aa the_aa purpose_aa of_aa defining _a as_aa well_aa as_aa designing_aa
the_aa software_aa system._aa
Another_aa vital_aa procurement_ policy_aa is_aa that_aa the_aa
vendor_aa must_aa honestly_aa and_a sincerely_aa communicate_aa
with_aa Uber_aa about_aa any_aa known_aa security_aa vulnerabilities_aa
or_aa loopholes_aa that_a may_aa act_aa as_aa a_aa serious_aa threat_aa
for_aa the_aa business._aa It_aa must_aa not_aa try_aa to_aa deceive_aa the_aa
mobility_aa business_aa or_aa share_aa inaccurate _aa information_aa
relating_aa to_aa its_aa software_aa applications_aa to_aa misguide_aa or_aa
cheat_aa the_aa business_a in_aa any_aa manner._aa The_aa role_aa of_aa
transparent_aa and_aa real-time_ communication_aa between_aa the_a
vendor_aa and_aa the_aa transport_aa business_aa entity_ is_aa of_a
cardinal_aa importance_aa to_aa make_aa sure_a that_aa both_aa can _a
work_aa together_aa in_a case_aa any_ gaps_aa arise_aa in_ the_aa
software_aa after_aa the_aa purchases_aa so_aa that_aa the_ issue_aa
can_aa be_aa effectively_aa resolved_aa (Hashim_ et_aa al.,_aa 2022)._aa
Effective_aa and_aa real-time_aa communication_aa between_aa the_a
vendor_aa and_aa Uber_aa is_aa a_aa vital_aa area_aa that_a can_aa
impact_aa the_aa procurement_ of _aa the _ software. _aa A _aa
detailed_aa documentation_aa must_aa be_aa in_aa place_aa which_aa
can_aa define_aa how_aa critical_aa information_aa will_aa pass_aa
along_aa the_aa key_aa stakeholders_aa so_aa that_aa transparency_aa
can_aa be_aa maintained_aa at_aa all_aa times._aa The_aa
communication_aa network_aa must_aa be_aa checked_aa to_ ensure_aa
its_aa real-time_ nature_aa so_aa that_aa the_aa vendor_ can_aa share_aa
important_aa information_aa with_ the_aa Uber_aa organization_aa
relating_aa to_aa diverse_aa areas_ such _aa as _aa potential _aa
vulnerabilities_aa that_aa may_aa be_aa inherent_aa in_aa the_aa
software_aa application._aa The_aa communication_aa must_aa be_aa
based_aa on_aa the_aa ongoing_aa monitoring_aa of_a the_aa software._aa
_aa
PROJECT_aa 4 19
The_aa vendor_a must_ possess_aa documentation_ that_aa proves_aa
that_aa the_aa software_aa that_aa it_aa has_aa developed_aa has_aa been_aa
monitored_aa throughout_aa the_a development_aa lifecycle_aa
process._aa This_aa proof_a must_aa be_aa presented_aa to_aa Uber_aa
to_aa ensure_aa that_a it_aa meets_aa the_aa necessary_ security_aa
requirements_aa of_aa the_a organization._aa
A_aa thorough_aa documentation_ review _ must_aa be_aa carried_aa
out_aa by_aa the_aa security_aa team_aa at_aa Uber_ to_aa check_aa the_aa
consistency_aa as_aa well_aa as_aa accuracy_aa of_aa the_aa vendor’s_a
software_aa development_aa lifecycle_aa process._a The_aa Uber_aa
business_aa has_aa to_a make_aa sure_aa that_aa the_aa selected_aa
vendor_aa shares_aa a_aa comprehensive_aa documentation_aa
record_aa that_aa can_aa be_aa reviewed_aa to_aa check_aa for_a any_aa
inconsistencies_aa or_aa gaps._aa aa_ Some_aa of_aa the_ key_aa
details_aa that_aa must_aa be_aa shared_aa for_aa validation_aa
purposes_aa include_aa important_aa terminologies,_aa technical_aa
specifications,_aa etc._aa
Supply_aa Chain_aa Cyber_aa Security_aa Risks
The_aa Uber_aa organization_aa relies_aa on_aa a_aa supply_aa chain_aa network,_a which _a enables_aa it_aa to_aa procure_aa appropriate_aa
software_aa applications_aa and_aa offer_aa seamless_aa mobility_aa solutions_a to_aa its_aa end_ users._aa A_aa diverse_aa range_aa of_a risks_a
PROJECT_aa 4 20
and_aa uncertainties_aa arise_aa in_aa the_aa supply_aa chain_aa of_aa the_aa business,_aa which_aa has_aa the_aa potential_aa its_aa ability_aa thrive_aa
and_aa sustain_aa itself_a in_aa the _ dynamic_aa and_aa competitive_aa market_aa setting._aa _aa
Cyber_aa security_aa implications_aa related_aa to_aa the_aa procurement_aa process
• Low_aa level_aa of_aa security_aa compliance_aa by_aa the_aa vendor_aa –_aa The_aa adoption_aa of_ a_aa poor _aa cyber_ security _aa
approach_aa by_aa the_aa selected_aa vendor_aa can_aa reflect_aa in_aa the_aa software_aa that_aa is_ developed_aa and_aa ultimately_aa
procured_aa by_aa Uber._aa Due_aa to_aa gaps_aa or_aa vulnerabilities_aa in_ the_aa software,_aa the_a risk_aa from_aa malicious_aa actors_aa
may_aa increase_aa for_aa the_aa business,_aa impacting_aa its_aa business_aa processes._aa
• Inefficiencies_aa in_aa software_aa due_aa to_ the_aa changing_aa nature_aa of_aa technology_aa –_aa The_aa changing_aa nature_aa
of_aa digital_a technologies_aa may_aa lead_aa to_aa the_ emergence_aa of_aa vulnerabilities_aa that_aa may_aa naturally_aa arise_aa
within_aa the_aa supply_a chain _aa network._aa Such_aa vulnerabilities_aa may_aa give_ rise_aa to _ opportunities _aa for _a
cybercriminals_aa to_aa inject_aa malware_aa or_aa carry_aa out_aa malicious_aa activities_aa in_ other_aa ways_aa and_aa compromise_aa
the_aa business_aa processes_aa of _ Uber._aa
• Data_aa leaks_aa –_aa The_aa leak_aa of_aa data_aa is_aa one_ of_a the_aa most_aa serious_aa forms_aa of_aa cyber_aa security_aa
consequences_aa that_aa may_aa arise_aa in_aa the_aa supply_aa chain_aa of_aa Uber_aa while_aa procuring_aa a_ software _aa solution. _aa
It_ may_aa be_aa due_ to_aa internal_aa or_aa external_aa factors_aa such_aa as_aa employees,_aa hackers_aa or,_aa cybercriminals,_aa etc._a
Regardless_aa of_aa who_aa is_aa responsible_aa for_a such_aa leaks,_aa it_aa may_ lead_aa to_aa detrimental_aa consequences_aa for_
Uber_aa and_aa weaken_ its_aa IT_aa ecosystem._aa aa_a aa_aa
PROJECT_aa 4 21
Recommendations_aa to_aa address_aa the_aa concerns
The_aa following_aa recommendations_aa have_aa been_aa developed_aa so_aa that_ Uber _a will _aa be _aa able _a to _aa effectively_aa
manage_aa and_aa control_aa the_aa cyber_aa security_aa implications_ relating_aa to_aa the_aa procurement_aa process._aa
• Conducting_aa a_aa thorough_aa check_aa of_aa the_aa vendor’s_aa cyber_aa security_aa approach_aa –_aa Before _ finalizing _
the_aa vendor_aa from_aa whom_aa software_aa will_aa be_aa procured,_aa Uber_aa must_aa make_aa sure_aa to_aa carry_aa out_aa a_aa
comprehensive_aa inspection_ of _aa the_aa vendor’s _aa cyber _aa security_aa approach _aa (Culot _aa et_aa al.,_aa 2019). _aa A _aa thorough _aa
compliance_aa testing_aa must_aa be_aa carried_aa out,_aa which_a will_aa help_aa to_aa ascertain_aa whether_aa the_aa vendor_aa is_aa
following_aa the_aa appropriate_aa industry_aa standards,_aa guidelines_aa and_aa internal_aa policies _a or_aa not,_aa regarding_aa the_
cyber_aa security_aa practices._aa Moreover,_aa it_aa is_aa essential_aa for_aa Uber_aa to_aa assess_aa the_aa cyber_aa security_aa culture_a
that_aa is_aa adopted_ within_aa the_aa organization_aa since_aa it_aa can_aa help_aa to_ determine_ the_aa vendor’s_a commitment_aa
to_aa develop_aa software_aa solutions_aa that_aa have_ robust_aa security_aa features._
• Deployment_aa of_aa a_aa well-defined_aa supply_aa chain_aa risk_aa management_aa (SCRM)_aa approach_aa -_aa The_aa supply_a
chain_aa risk_aa management_ process_aa refers_aa to_aa the_aa approach_aa by_aa which_aa the_aa risks_ associated_aa with_aa the_aa
procurement_aa of_aa software_aa or_aa its_aa components_aa are_aa reviewed_aa on_aa an_aa ongoing_aa basis_aa and_aa effectively_aa
addressed._aa In_ the_aa context_aa of_aa the_aa Uber_aa organization,_aa a_aa SCRM_aa must_aa be_aa designed_aa so_aa that_aa the_aa
firm_aa can_aa be_aa well-prepared_aa to_aa deal_ with _aa threats_aa that _aa naturally _ arise. _aa The _aa SCRM _aa will _ help _aa Uber _aa
PROJECT_aa 4 22
follow_aa a_aa methodical_aa process_aa for_aa identifying,_aa analyzing_aa and_aa mitigating _aa risks _aa that_a may_a arise_aa within_aa
the_aa supply_aa chain_ in_aa a_ timely_aa and_aa efficient_aa manner_aa (Gurtu_aa &_ Johny,_aa 2021)._aa _aa
• Adoption_aa of_aa a_aa risk-based_aa strategy_aa –_aa Uber_aa must_aa adopt_aa a_aa risk-based_aa approach_aa to_aa manage_aa its_
supply_aa chain_aa network._ It_aa will_aa enable_aa the_aa transport_aa and_aa mobility_aa business _ to_a manage_aa its_aa supply_aa
chain_aa network_aa in_aa an_aa adaptable_aa manner_aa and_aa ensure_aa that_aa it_aa is_aa able_aa to_aa keep_aa track_aa of_aa any_aa kind_aa
of_aa abnormalities_aa that_aa arise_aa within_aa the_aa network_aa (Hermoso-Orzáez_aa &_aa Garzón-Moreno,_aa 2022)._aa The_aa
involvement_aa of_aa the_aa cyber_aa security_aa team_aa within_aa the_aa supply_aa chain_aa is_aa instrumental_aa so_aa that_aa
appropriate_aa security_aa measures_aa are_aa in_aa place_aa that_aa can_aa enable_aa the_aa organization_aa to_aa promptly_aa react_aa and_aa
respond_aa to_aa any_a cyber_aa security_aa implications_aa in_aa the_a procurement_aa process._aa
Appropriate_aa supply_aa chain_aa risk_ management_aa practices
Uber_aa can_aa deploy_aa a_aa number_aa of_aa effective_a supply_aa chain_aa risk_aa management_aa practices_aa so_aa that_aa it_aa can_aa
securely_aa procure_aa software_aa applications_aa to_aa strengthen_aa its_aa IT_aa infrastructure._aa aa_aa
• Improving_aa the_aa visibility_aa of_aa the_aa supply_aa chain_aa network_aa –_aa As_aa a_aa diverse_aa range_aa of_aa actors_aa are_aa
involved_aa in_aa a_aa supply_aa chain,_aa the_a visibility_aa of_ the_a activities_aa within_aa the_aa network_aa may_aa be_a limited._aa
It_ is_aa instrumental_aa for_aa Uber_aa to_aa ensure_aa that_aa the_aa supply_aa chain_aa is_ supported_aa by_aa a_ transparent_aa
communication_aa network._aa It_aa can_aa ensure_aa that_aa information_aa exchange_aa takes_aa place_aa in_aa a_aa seamless_aa manner_aa
on_aa a_aa real-time_aa basis_aa (Spieske_a &_aa Birkel,_aa 2021)._a
PROJECT_aa 4 23
• Development_aa of_aa a_aa contingency_aa and_ change_aa management_aa plan_aa – _aa A _aa well-defined_aa contingency_aa
plan_aa and_aa change_aa management_aa plan_aa must_aa be_a developed,_aa which_aa can_aa be_aa adopted_aa in_aa case_aa any_aa kind_aa
of_aa threats_aa or_aa risks_aa arise_a in_aa the_aa supply _ chain _aa activities _aa of _a the _aa business. _aa Such _ plans _aa can _aa ensure _aa
that_aa the_aa business_ can_aa promptly_aa respond_aa to_aa the_aa situation_aa and_aa resolve_aa the_aa issue_aa to_aa the_aa best_aa of_aa
its_aa ability.
• Real-time_aa monitoring_aa of_aa risks_aa –_aa A_aa real-time_aa monitoring_aa of_aa risk_aa must_aa be_aa undertaken_aa within_a the_aa
supply_aa chain_aa at_aa all _ times._aa It_aa can_aa ensure_aa that_aa there_aa is_aa better_aa control_aa over_aa supply_aa chain_a stages,_aa
and_aa each_aa member_aa can_aa participate_a to_aa manage_aa and_aa mitigate_aa the_ risks._aa
As_aa Uber_aa heavily_aa relies_aa on_a technology,_aa including_aa procured_aa software_aa applications,_aa it_aa is_aa instrumental_aa for_aa
the_aa transport_aa business_aa to_a integrate _ appropriate _aa supply _aa chain _aa risk _aa management_aa practices._aa Such_aa practices_aa can_aa
play_aa a_aa strategic_aa role_aa to_a make_aa sure_ that_aa the_aa risks_ and_aa threats_aa that_aa arise_aa while_aa procuring_aa a_a software_aa
solution_aa can_aa be_aa effectively_aa managed._aa
Acquisition_aa Alignment
In_a the_aa context_aa of_aa Uber_aa organization,_aa the_aa proper_aa alignment_a of_aa the_aa acquisition,_aa procurement,_aa and_aa
outsourcing_aa of_aa software_aa applications_aa is_aa essential_aa to_aa make_aa sure_aa that_aa it_aa plays_aa a_aa cardinal_aa role_aa to_aa help_aa
achieve_aa the_aa organization’s_aa information_aa security_aa goal._aa An_aa acquisition_aa alignment_aa strategic_aa approach_aa has_aa been_aa
PROJECT_aa 4 24
developed_aa that_aa can_aa enable_aa the_aa business_aa entity_aa to_ ensure_aa that_ all _aa functions _aa are _aa synced _aa with _aa each _aa other. _aa
The_aa following_aa activities_aa and_aa practices_aa need_aa to_aa be_aa undertaken_aa to_aa ensure_aa proper_aa alignment._aa
Request_aa for_aa information_aa –_aa The_aa initial_aa stage_aa involves_ requesting_aa the_aa vendor_aa for_aa appropriate_aa information._aa
The_aa information_aa must_aa be_ thoroughly_aa examined_aa to_aa ensure_aa that_aa the_aa vendor_aa complies_aa with_aa the_a necessary_aa
industry_aa regulations_aa and_aa standards._aa It_aa can_aa assist_aa Uber_aa to_ evaluate_aa the_aa vendor,conduct_aa document_aa review_aa
and_aa assess_aa the_aa vendor’s_aa capabilities_aa at_aa an_aa in-depth_aa level_ and_aa ascertain_aa whether_aa it_aa can_aa meet_ its_aa
software_aa requirements_aa or_aa not._a
Proceeding_aa through_aa acquisition_aa –_aa For_aa ensuring_aa proper_aa alignment,_aa robust_aa communication_aa will_ play_aa an_aa in_aa
integral_aa role_aa while_aa advancing_aa through_aa the_aa acquisition_aa process._aa Uber_aa must_aa ensure_aa to_aa engage_aa with_aa the_aa
selected_aa vendor_aa and_aa clearly_aa present_aa its_aa requirements_aa and_aa expectations._aa Such_aa an_aa approach_aa must_aa be_
adopted_aa so_aa that_ there_aa will_aa be_aa utmost_aa clarity_aa in_aa terms_aa of_aa what_aa the_aa mobility_aa business_aa intends_aa from_ the_aa
software_aa provider_aa and_aa the_a possibility_aa of_aa variance_aa in_aa the_ software _aa solution_aa can_aa be_aa diminished._aa _aa
Testing_aa activities_aa –_aa Testing _ is _aa one _aa of _aa the _aa key _aa activities _aa that _aa must _aa be _aa carried _aa out _aa by _aa Uber _aa after _aa
the_aa acquisition_aa has_aa been_aa done._aa Testing_aa is_aa instrumental_aa since_aa it_ can _aa help_aa to_ ensure_aa quality_aa assurance._aa
Moreover,_aa it_aa can_aa also_ help _aa to _aa identify _ any _aa possible _aa gaps _aa or _aa vulnerabilities _ that _ may _aa exist _aa within _aa the _aa
PROJECT_aa 4 25
software_a application_aa so_aa that_aa appropriate_aa actions_aa can_aa be_aa taken_aa to_aa address_aa the_aa same_aa (Graham_aa et_aa al.,_aa
2021)._aa Diverse_aa kinds_aa of_aa testing_aa can_aa be_aa carried_aa out_aa such_aa as_aa compliance_aa testing,_aa security_aa testing,_aa
performance_aa testing,_aa etc._aa to_aa make_aa sure_aa that_ the_aa software_aa that_aa has_aa been_aa procured_ can_aa carry_aa out_aa the_aa
necessary_aa functions_aa and_aa activities_aa for_aa which_aa it_aa has_aa been_aa acquired._aa An_aa in-depth_aa testing_aa is_aa a_aa vital_
aspect_aa (Spillner_aa &_ Linz,_aa 2021)_aa that_aa must_aa be_aa prioritized_aa since_aa it_a can_aa support_aa acquisition_aa alignment._
Implementation_aa of_aa software_aa –_aa The_aa implementation_aa of_aa the_aa procured_aa software_aa application_aa is_aa an_aa important_aa
activity_aa which_aa will_aa enable_aa Uber_ to_aa utilize_aa the_a software_aa and_ its_aa features_aa in_a the_aa practical_aa business_aa
context._aa The_aa implementation_ must _aa be _aa conducted _aa in _aa a _aa precise _aa manner _aa so _aa that _aa no _aa gaps _aa will _aa arise _aa and _aa
the_aa software_aa can_a seamlessly_aa and_aa efficiently_aa carry_aa out_aa the_aa necessary_aa operations_aa for_aa which_aa it_aa has_aa been_aa
acquired_aa (Bossen_ et_aa al.,_aa 2021)._aa It_aa is_aa a_aa vital_aa process_aa that_aa will_aa ensure_aa that_aa it_aa is_aa fused_aa with_aa the_aa
workflow_aa of_aa Uber_aa and_aa it_aa can_aa enable_aa the_aa mobility_aa company_aa to_ optimally_aa manage_aa it_aa activities_aa and_aa
protocols._aa
The_aa ongoing_aa maintenance_aa of_aa the_aa application_aa –_aa The_aa final_aa activity_aa that_aa Uber_aa needs_aa to_aa lay_aa emphasis_aa
on_aa to_aa ensure_aa the_aa alignment_aa of_aa key_ business_aa functions_aa is_aa related_aa to_aa the_aa regular_aa maintenance_aa of_aa the_aa
software._aa The_aa software_aa application_ that_aa has_aa been _aa procured _aa by _aa the _aa business_aa must_aa be _aa maintained _aa on _aa an_aa
ongoing_aa basis_aa since_aa it_aa can_aa help_aa to_aa fix_aa issues,_aa make_aa patches_aa and_aa introduce_aa updates_aa in_ a_aa timely_aa
PROJECT_aa 4 26
manner._aa The_aa proper_aa maintenance_aa of_aa software_aa is _aa vital _aa since _aa it _aa can _aa strengthen _aa the _a IT _aa capability _aa of_ the _aa
business._aa
Software_aa Risk_aa Mitigation_aa Recommendations
The_aa technological_aa landscape_aa in_aa which_aa Uber_aa operates_aa is_aa highly_aa dynamic_aa which_aa increases_aa the_aa risks_aa
and_aa threats_aa that_aa it_aa is_aa exposed_aa to._aa On_aa the_aa basis_aa of_aa the_aa thorough_aa vulnerability_aa analysis,_aa a_aa number_aa of_aa
software_aa risk_aa mitigation_ recommendations_aa have_aa been_aa developed_aa for_aa the_aa company._aa By_aa deploying_aa these_aa
measures_aa in_aa place,_aa the_ business_aa entity_aa will_ be_aa better_aa prepared_aa to_aa deal_aa with_a the_aa risks_aa and_aa
vulnerabilities_aa that_aa may_aa arise_aa relating_aa to_aa its_aa software_aa applications._aa These_aa recommendations_aa can_aa help_aa the_aa
business_aa to_aa strengthen_aa the_aa cyber_aa security_ strength_aa of_aa its_aa software_aa infrastructure_aa and_aa the_aa overall_aa IT_aa
ecosystem.
Compliance_aa testing_aa of_aa software_aa vendor_aa before_aa the_aa finalization_aa process_aa –_a While_aa procuring_aa software_aa
applications_aa from_aa a_aa third-party_aa i.e._aa a_aa vendor,_aa it_aa is_aa instrumental_aa for_aa Uber_aa to_aa carry_aa out_aa a_aa rigorous _a and_aa
thorough_aa compliance_aa testing_aa of_aa the_aa party._aa Such_aa a_aa testing_aa will_aa enable_aa the_ business_aa to_aa get_aa a_aa detailed_aa
insight_aa into_a the_aa security _ measures _aa that _a have _ been_aa taken_aa by_ the_aa vendor _aa while _aa designing_aa the_aa software. _aa
It_ will_aa also_aa enable_aa the_aa business_aa to_aa identify_aa any _ loopholes,_aa bugs_aa or_aa errors_aa in_aa the_aa software_aa which_aa
could_aa lead_aa to_aa the_aa exploitation_aa of_aa software_aa by_aa any_aa malicious_aa actors._aa By_aa carrying_aa out_aa an_aa integrated_aa
PROJECT_aa 4 27
inspection_aa along_aa with_aa compliance_aa testing,_aa Uber_aa can_aa analyze_aa the_aa strength_aa of_aa the_aa vendor’s_aa cyber_aa security_aa
approach_aa (Culot_aa et_aa al.,_aa 2019).
Performing_aa a_aa source_aa code_aa analysis_aa –_aa Uber_aa must_aa engage_aa in_aa carrying_ out _aa a _aa detailed _aa source _aa code _aa
analysis_aa since_a it_aa serves_aa as_aa a_aa useful_aa method_aa that_aa can_aa aid_aa in_a performing_a the_aa audit_aa of_aa software._aa In_aa
this_aa analysis,_aa the_aa mobility_aa business_aa can_aa utilize_aa a_a scanner_aa in_aa order_aa to_aa locate_aa potential_aa trouble_aa spots_aa
that_aa may_aa exist_aa in_aa the_aa source_a code_aa of_aa the_aa software_aa that_aa is_aa being_aa procured_aa by_aa a_aa vendor_aa (Kaur_aa &_aa
Nayyar,_aa 2020)._aa After_aa locating_aa the_ issue_aa area,_aa the_aa security_aa team_aa of_aa Uber_aa can_aa carry_aa out_aa a_ manual_aa
auditing_aa process_aa to_ get_aa a_aa better_aa insight_aa into_aa the_aa security_aa concerns_aa associated_aa with_aa software_aa applications._aa
Conducting_aa security_aa testing_aa –_aa As_ technology_aa is_aa evolving_aa on_aa a_ constant_aa basis,_aa it_aa is_ instrumental_aa for_aa
Uber_aa to_aa carry_aa out_aa a_aa systematic_aa security_aa testing_aa process _aa involving_aa its_aa software_aa applications._aa Such_aa a_aa
procedure_aa may_aa involve_aa activities_aa such_aa as_aa penetration_aa testing,_aa vulnerability_aa scanning,_aa access_aa control,_aa etc.,_aa
and_aa Uber_a will_aa be_ able_ to_aa identify_aa any_aa gaps,_a and_a vulnerabilities_aa that_aa may_aa exist_aa within_aa the_aa software._aa
Such_aa a_aa testing_aa activity_aa will_aa enable_aa the_aa transport_a business_aa to_aa take_aa prompt_aa actions_aa and_aa effectively_aa
mitigate_aa software_aa risks.
Change_aa management_aa –_aa A_ well-defined_aa change _aa management _ process _a must _aa be _aa followed_aa within_aa the_aa
organization._aa Such_aa a_aa procedure_aa will_aa enable_aa Uber_aa to_aa keep_aa a_aa constant_aa tab_aa on_aa the_aa changes_aa that_aa have_aa
PROJECT_aa 4 28
taken_aa place_aa in_aa the_ software _aa relating _aa to _aa frequent _aa upgrades, _aa patches, _aa etc. _aa The _aa business _aa must _aa prioritize _aa the _aa
change_aa management_aa process_aa so_a that_aa it_aa will_a be_aa able_aa to_ manage_aa the_aa software_aa updating_aa process_aa in_aa a_aa
streamlined_aa manner_aa and_aa there_aa will_aa be_aa a_a better_ degree_aa of_ control_aa over_aa the_a software_aa applications_ that_aa
have_aa been_aa procured_aa from_aa vendors._aa
Emphasis_aa on_aa user_aa training_aa and_aa support_aa aspect_aa _aa –_aa While_aa procuring_aa new_aa software,_aa Uber_aa must_aa take_aa
into_aa account_aa the_aa training_aa aspects_aa since_aa they_aa may_aa influence_aa the_aa ability_aa to_aa use_aa the_aa software_ in_ a_aa safe_aa
and_a secure_aa manner_aa by_aa the_aa staff._aa It_aa is_aa imperative_aa to_aa focus_aa on_aa the_aa availability_aa of_aa training_aa options_aa for_aa
the_aa end_aa users_aa of_aa the_aa software_aa so_aa that_aa they_aa can_aa efficiently_aa use_aa the_aa software_aa and_aa be_aa able_aa to_aa identify_aa
as_aa well_ as_aa report_aa the _aa errors _aa or _ issues _aa that_aa they_aa come_aa across_aa while_aa using_aa the_aa software._aa The_aa quality_aa
of_aa the_aa training_aa that_aa is_aa made_aa available_aa for_aa the_aa employees_aa of_aa Uber_aa must_aa be_aa given_aa high_aa emphasis_aa
since_aa it_ can _aa empower_aa them_aa to_aa identify_aa potential_ gaps_a that _ may_aa give_aa rise_aa to_aa security_a concerns_aa while_aa
using_aa the_aa software_aa for_aa business_aa purposes._aa
Integration_aa of_aa cyber_aa security_aa measures_aa within_aa the_aa supply_aa chain_a network_aa –_aa As_aa the_aa possibility_aa of_aa
cyber_aa security_ risks_aa and_aa threats _ to _aa arise_aa within_aa the_aa supply_aa chain_aa network_aa is_aa high,_aa Uber _ must _aa make _aa
sure_aa to_a integrate_aa cyber_aa security_aa within_aa it._aa Such_aa an_aa approach_aa will_aa enable_aa the_ transport_aa business_aa to_aa
identify_aa anomalies_aa in_aa the_aa network_aa that_aa may_aa compromise_aa the_aa quality_aa of_a the_aa software_aa applications _aa that_aa
PROJECT_aa 4 29
are_aa being_aa procured._aa A_aa robust_aa supply_a chain_aa risk_aa management_aa (SCRM)_a must_aa be_aa in_aa place _ that_aa will_aa
support_aa the_aa fusion_aa of_aa cyber_aa security_aa elements_aa within_aa the_aa entire_aa network._aa
The_aa recommendations_aa that_aa have_aa been_aa made_aa will_aa enable_aa Uber_aa to_aa effectively_aa manage_ and_aa mitigate_aa the_aa
risks_aa and_aa vulnerabilities_aa that_aa may_aa arise_aa relating_aa to_aa the_aa software_aa applications_aa that_aa are_aa used_ by_aa the_aa
business._aa The_aa business_aa must_aa ensure_aa that_aa suitable_aa measures_aa are_aa introduced _aa at_aa diverse_aa levels_ to_aa curb_aa
uncertainties_aa relating_aa to_aa the_aa software_ that_aa make_aa up_ the_aa IT_aa ecosystem_aa of_aa the_aa company._aa aa_aa
PROJECT_aa 4 30
Reference
Arishina,_aa Y.,_a Hu,_aa Y._ H._aa F.,_aa &_aa Hoppa,_aa M._aa A._aa (2022, _a March)._aa A_aa Study_ of_aa Video_aa Conferencing_a
Software_aa Risks_aa and_aa Mitigation_ Strategies._aa In_aa Journal_aa of_aa The_aa Colloquium_aa for_aa Information_aa Systems_aa
Security_aa Education_aa (Vol._ 9,_aa No._aa 1,_aa pp._aa 10-10).
Ayman,_aa A.,_aa BAlhamaki,_aa A.,_aa &_aa Abdellatif,_aa M._aa H._aa (2020,_aa July)._aa A_aa new_aa integrated_aa product_aa and_aa process_aa
development_aa model._a In_aa The _aa International_aa Conference_aa on_aa Applied_aa Mechanics_aa and_aa Mechanical_aa
Engineering_aa (Vol._aa 19,_aa No._ 19th_aa International _aa Conference_aa on_aa Applied_aa Mechanics_aa and_ Mechanical_aa
Engineering.,_aa pp._aa 1-10)._aa Military_a Technical_aa College.
Bossen,_aa F.,_aa Sühring,_ K.,_aa Wieckowski,_ A.,_aa & _aa Liu, _aa S. _aa (2021)._aa VVC _aa complexity _aa and _aa software_a
implementation_aa analysis._aa IEEE_aa Transactions_aa on_aa Circuits_aa and_aa Systems_aa for_aa Video_aa Technology,_aa 31(10),_aa
3765-3778.
PROJECT_aa 4 31
Culot,_aa G.,_aa Fattori,_aa F.,_aa Podrecca,_aa M.,_aa &_aa Sartor,_aa M._aa (2019)._aa Addressing_aa industry_aa 4.0_aa cybersecurity_aa
challenges._aa IEEE_aa Engineering_aa Management_aa Review,_aa 47(3),_aa 79-86.
Dissanayake,_aa N.,_ Jayatilaka,_aa A.,_aa Zahedi,_aa M.,_aa &_aa Babar, _ M. _aa A. _aa (2022). _ Software _aa security _aa patch _ management-
A_aa systematic_aa literature_aa review_aa of_aa challenges,_aa approaches,_aa tools_aa and_aa practices._aa Information_aa and_aa
Software_aa Technology,_aa 144,_aa 106771.
Goericke,_aa S._aa (2020)._ The _aa future _aa of _ software _aa quality _aa assurance_aa (p._aa 257)._aa Springer_aa Nature.
Gonzalez,_aa C.,_a Aharonov-Majar,_aa E.,_aa &_aa Rajivan,_aa P._aa (2020)._a Update_aa now_aa or_aa later?_aa Effects_aa of_aa experience,_aa
cost,_aa and_aa risk_ preference _aa on_ update_aa decisions._aa Journal_aa of_aa Cybersecurity,_aa 6(1),_aa tyaa002.
Graham,_aa D.,_aa Black,_aa R.,_aa &_ Van _ Veenendaal,_aa E._aa (2021)._aa Foundations_aa of_aa software_aa testing_aa ISTQB_aa
Certification._aa Cengage_aa Learning.
Gurtu,_aa A.,_aa &_aa Johny,_aa J._aa (2021)._aa Supply_aa chain_aa risk_aa management:_aa Literature_aa review._aa Risks,_a 9(1),_aa 16.
Hashim,_aa N._aa L.,_aa Yusof,_aa N.,_aa Hussain,_aa A.,_aa &_aa Ibrahim,_aa M._aa (2022)._aa User_aa Experience_aa Dimensions_ for_aa E-
procurement:_aa A_aa Systematic_aa Review._aa Journal _aa of _aa Information _aa and _aa Communication _aa Technology, _aa 21(4), _aa
465-494.
PROJECT_aa 4 32
Hermoso-Orzáez,_aa M._ J.,_aa &_aa Garzón-Moreno,_aa J. _aa (2022)._aa Risk _aa management_aa methodology_aa in_aa the _ supply _aa
chain:_aa a_aa case_ study _aa applied. _aa Annals _aa of _aa Operations _aa Research,_aa 313(2),_aa 1051-1075.
ISO/IEC_aa 27001_aa Standard_aa –_aa Information_aa Security_aa Management_aa Systems._aa (n.d.)._a ISO._aa
https://www.iso.org/standard/27001n
Kaur,_aa A.,_aa &_a Nayyar,_aa R._aa (2020)._aa A_aa comparative_a study_aa of_aa static_aa code_aa analysis_a tools_aa for_aa vulnerability_aa
detection_aa in_aa c/c++_aa and_aa java_aa source_aa code._aa Procedia _aa Computer_aa Science,_aa 171,_aa 2023-2029.
Mohammed,_aa I.,_aa &_aa Bade,_aa A._aa M._aa (2019)._aa Cybersecurity_aa capability_aa maturity_aa model_aa for_aa network_aa system._aa
International_aa Journal_aa of_aa Development_aa Research, _aa 9(07), _aa 28637-28641.
Mohialden,_aa Y._aa M.,_ Hussien,_aa N._aa M.,_aa &_aa Hameed,_aa S._aa A._aa (2022)._aa Review_aa of_aa Software_aa Testing_aa Methods._
Journal_aa La_aa Multiapp,_aa 3(3),_aa 104-112.
Saeed,_a S.,_aa Jhanjhi,_aa N._aa Z.,_aa Naqvi,_aa M.,_aa &_aa Humayun,_aa M._aa (2019)._aa Analysis_aa of_aa software_aa development_aa
methodologies._aa International_aa Journal_aa of_aa Computing_aa and_aa Digital_aa Systems, _aa 8(5), _aa 446-460.
PROJECT_aa 4 33
Sasmito,_aa G._aa W.,_aa &_ Nishom,_aa M._a (2019,_aa December)._aa Usability_aa testing_aa based_aa on_ system_aa usability_aa scale_aa
and_aa net_ promoter_aa score. _aa In_aa 2019 _aa International _aa Seminar _aa on _aa Research _aa of _aa Information _aa Technology _aa
and_aa Intelligent_aa Systems_aa (ISRITI)_aa (pp._aa 540-545)._aa IEEE.
Slapničar,_aa S.,_aa Vuko,_aa T.,_aa Čular,_aa M.,_aa &_aa Drašček,_aa M._aa (2022)._aa Effectiveness_aa of_ cybersecurity_aa audit._aa
International_aa Journal_aa of_aa Accounting_aa Information_aa Systems, _aa 44, _ 100548.
Spieske,_aa A.,_ &_aa Birkel,_ H. _aa (2021). _a Improving _aa supply _aa chain _aa resilience _aa through _aa industry _aa 4.0: _aa A _aa systematic _aa
literature_aa review_aa under_aa the_aa impressions_aa of_ the _aa COVID-19_aa pandemic. _aa Computers _aa & _aa Industrial_aa
Engineering,_aa 158,_aa 107452.
Spillner,_aa A.,_aa &_aa Linz,_aa T._aa (2021)._aa Software_aa Testing_aa Foundations:_aa A_aa Study_aa Guide_aa for_aa the_aa Certified_aa
Tester_aa Exam-Foundation_aa Level-ISTQB®_aa Compliant._aa
Yaacoub,_ J._aa P._aa A.,_aa Noura,_aa H._aa N.,_aa Salman,_aa O.,_aa &_aa Chehab,_aa A._aa (2022)._aa Robotics_aa cyber_aa security:_a
Vulnerabilities,_aa attacks,_aa countermeasures,_aa and_aa recommendations._aa International_aa Journal_aa of_aa Information_aa
Security.