Risks Associated with Hardware, Software, and Services
Organizations cannot operate solely alone; there are many dependencies and interconnections that organizations have with their entire supply chain, which includes suppliers, vendors, contractors and customers.
2 slides · 1 min read · Domain 1
There are various risks associated with hardware, software, and services, and the following is a list of some of them:
HARDWARE
Organizations buy various hardware, laptops, desktops, servers, cameras, OT devices, etc. In manufacturing facilities, it is very common to find unique dedicated and sometimes legacy systems. Such systems are used in many assembly lines and pose a hardware risk since manufacturing is dependent on them. There is also a software risk since they run old software and service risks and, in many cases, these systems are maintained solely by the system provider.
SOFTWARE
May include bugs and improperly designed functions that can be exploited by attackers. Defects that are discovered by attackers after a product has shipped and been put into production, without the knowledge of either the vendor or users, are known as "zero-day" exploits, as attackers can use these vulnerabilities indiscriminately for the time it takes until a patch or solution is created to resolve the defect.
SERVICES
Attacking a small supplier of various large companies can be much easier than attacking large, highly protected companies. That was the logic that served the bad actors in the Target incident. Another issue is the rewards, as we saw in the SolarWinds incident, affecting one service provider allowed the bad actor infect thousands of organizations.
