Overview
As awareness of potential cyber threats has grown over the past decade, asset owners in many critical infrastructure sectors now recognize the need to better secure their automation systems. While many standards and associated guidance documents are available that describe what must be done, it can be challenging to define the best approach for each situation.
Protective, preventive, and compensating measures are effective for securing existing products and solutions, but for new or enhanced products, suppliers must include security features during design and development. Many major suppliers are already doing this, but they typically prefer to develop and deliver new functional capabilities and features that are more likely to provide them with a competitive advantage. Suppliers will only view enhanced security as a differentiator if customers include it in the set of desired features.
Cybersecurity Needs to be Addressed In All Procurement Documents
Prospective buyers are responsible for ensuring that security features are included when assessing and selecting new technology. This is best addressed by including security requirements in the request for proposal (RFP) or request for quotation (RFQ) documents sent to suppliers. Available guidance documents can help asset owners select the most appropriate language for this purpose.
ARC Advisory Group clients can view the complete report at ARC Main Client Portal or at ARC Office 365 Client Portal
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Cybersecurity, Procurement Process, RFI, RFP, RFQ, Secure by Design, ARC Advisory Group.