Supply Chain Attack

A supply chain attack goes after a weaker link in a software or hardware supply chain instead of hitting the ultimate target head-on. The 2020 SolarWinds compromise is the textbook case: attackers slipped malicious code into a legitimate software update that thousands of organizations then installed themselves, trusting the vendor’s signature.

These attacks are so effective because they abuse trust that is already in place. Once a vendor’s product is approved inside your network, a tainted update rides in through the front door and sails past controls that would stop an external intruder. Defending against this is uncomfortable because much of the risk sits outside your direct control. It pushes security into vendor assessments, software bills of materials, code signing, and integrity checks on updates. The practical takeaway is that your posture is only as strong as that of the third parties you have chosen to trust, and most organizations trust more of them than they realize.

Why does supply chain security matter for the CISSP exam?

Supply chain risk sits in Domain 1: Security and Risk Management and touches Security Architecture. Know vendor assessment, software integrity verification, and how contracts and audits reduce third-party risk. CISA maintains guidance on ICT supply chain risk management.

Related terms: Threat Modeling, Risk Management