Including Cybersecurity in the Procurement Process

Author photo: Eric Cosman
ByEric Cosman
Category:
ARC Report Abstract

Overview

As awareness of potential cyber threats has grown over the past decade, asset owners in many critical infrastructure sectors now recognize the need to better secure their automation systems.  While many standards and associated guidance documents are available that describe what must be done, it can be challenging to define the best approach for each situation.

Protective, preventive, and compensating measures are effective for securing existing products and solutions, but for new or enhanced products, suppliers must include security features during design and development.  Many major suppliers are already doing this, but they typically prefer to develop and deliver new functional capabilities and features that are more likely to provide them with a competitive advantage.  Suppliers will only view enhanced security as a differentiator if customers include it in the set of desired features.

Cybersecurity Needs to be Addressed In All Procurement Documents

cybersecurity procurement cyberprocurement.jpgProspective buyers are responsible for ensuring that security features are included when assessing and selecting new technology.  This is best addressed by including security requirements in the request for proposal (RFP) or request for quotation (RFQ) documents sent to suppliers.  Available guidance documents can help asset owners select the most appropriate language for this purpose.

ARC Advisory Group clients can view the complete report at ARC Main Client Portal or at ARC Office 365 Client Portal

If you would like to buy this report or obtain information about how to become a client, please Contact Us    

Keywords: Cybersecurity, Procurement Process, RFI, RFP, RFQ, Secure by Design, ARC Advisory Group.

 

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients