risk
Malicious supply-chain injection of tampered hardware/software
Adversary creates false-front suppliers or intercepts the supply chain to insert counterfeit or tampered hardware, corrupted software/firmware, or malicious components into products and information systems.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Third-Party / Supply-Chain Risk
- Secure Development (SDLC) & Application Security
- Secure Configuration & Change Management
- taxonomy
- nist-800-30-threat-event
- nist-800-30-threat-source
- iso-27005-threat
- inherent_rating
- high
Details
- risk_id
- tprm-supply-chain-injection
- category
- cyber_security
- likelihood
- low
- impact
- critical
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
- nist-800-30-threat-source
- iso-27005-threat
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-05 — Include suppliers in incident notification and response mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Supplier notification of supply-chain compromises plus pre-planned coordinated response cuts detection and containment time for injected tampered components.
- UC-CONFIG-08 — Control maintenance tools, personnel, and remote sessions mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- related
- rationale
- Inspecting maintenance tools/media for tampering blocks one narrow injection vector, but broad authenticity/integrity verification of acquired hardware and software (UC-CONFIG-06) is the operative supply-chain-injection defense.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Provenance and BOM records, chain-of-custody, tamper-evident packaging, receipt inspection, and authenticity verification directly detect counterfeit and tampered hardware and components.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- related
- rationale
- Protected dependency baselines and configuration-integrity verification help detect tampered or counterfeit components.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before award defend against false-front and compromised suppliers.
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- related
- rationale
- Screening developers of critical systems and reviewing deliverables reduces malicious insertion via outsourced development.
- UC-CONFIG-06 — Verify authenticity and integrity of hardware and software mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Verifying digital signatures/integrity and sourcing from trusted suppliers before use directly blocks tampered or counterfeit hardware and software from entering.
- UC-TPRM-09 — Protect supply chain information through OPSEC mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Protecting sensitive info on suppliers, shipments, configurations, and delivery schedules from adversary collection denies the intelligence needed to intercept and inject into the supply chain.
- UC-SDLC-11 — Apply specialized development to critical components mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Custom/specialized reimplementation of critical components explicitly reduces supply-chain injection of tampered third-party parts.