You Outsource the Service but Not the Risk: Supply Chain Risk Management for the Cyber Security of Safety Critical Systems
Chris Johnson · ENLIGHTEN (Jurnal Bimbingan dan Konseling Islam) · 2016
Companies increasingly form interdependent relationships between contractors and sub-contractors that extend across national borders and legal jurisdictions. In consequence, supply chain risk management (SCRM) is an increasing concern for the cyber security of safety-critical systems. The following pages argue that outsourcing undermines SCRM by eroding technical expertise, which companies need to select and audit their suppliers. They are still held accountable when the failure of a sub-contractor jeopardizes the continuity of critical national infrastructures. Subsequent sections present SCRM techniques that support the cyber-security of safety-critical applications and at the same time help to realize the benefits of vertical market integration. Rather than de-risking, the aim of the paper is to reiterate that ‘safety-critical organizations outsource the service but they do not outsource the risk’.