Conceptual Framework for The Protection of Critical Information Infrastructure Against Supply Chain Threats

Ayaeze Paul, Ozogwu Young, Victor Emmanuel Kulugh, Ajishe Oyelola, Achimugu Andrew, Akiga Jessica, Akinremi Soji, N Patrick, Idris Muhammad, Asher Moses · International Journal of Latest Technology in Engineering Management & Applied Science · 2025

Abstract: The backbone of modern economies relies heavily on Critical Information Infrastructure (CII). It helps to provide critical services in the energy, finance, telecommunications, health, and transportation sectors. This growing dependences on third-party vendors, software applications, and supply chains, has exposed CII to formidable cyber risks. Recent attacks like SolarWinds, NotPetya, and Colonial Pipeline show how damaging supply chain cyber-attacks can be. They threaten both national security and economic stability. This paper hence presents a general conceptual framework that protects CII against supply chain threats. Anchored on the DSR approach, the paper synthesizes some of the literature on prior cybersecurity frameworks, models of supply chain risk, and resilience strategies. The proposed framework integrates three layers: Risk Identification, Governance and Compliance, and Resilience and Response. These layers introduce AI-driven threat detection, ZTA, secure procurement policy, and automated mechanisms for incident response. A comparison of major cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, C-SCRM, and the EU NIS2 Directive shows important gaps in risk assessment, regulation, and resilience strategies. The study therefore contributes to both the academic fraternity and industry practices through the presentation of a structured, adaptive model in mitigating evolving supply chain cyber risks. Future research on empirical validation, cross-border regulatory harmonization, and real-time risk quantification models will be useful in further enhancing global CII resilience.

Read the paper · More papers on PaperTik