CYBER DEFENSE MODEL FOR THE SUPPLY CHAIN
Keywords:
cybersecurity, supply chain, cyber defense, information systems, software supply chain, SBOM, cyber risk, Defense in DepthAbstract
The increasing dependence of modern information systems on external suppliers, cloud services, software libraries, updates and managed services makes the supply chain a critical component of cybersecurity. The compromise of a single supplier or software component may provide an entry point into multiple interconnected information systems and result in cascading cyber impacts.
This study proposes a multi-layer cyber defense model for supply chains consisting of seven interconnected protection layers: supplier verification, component integrity control, access protection, dependency monitoring, threat detection, propagation control, and incident response and recovery. A distinctive element of the proposed model is the propagation control mechanism, which aims to isolate a compromised external component before the compromise reaches critical information assets.
Downloads
References
[1] European Union Agency for Cybersecurity (ENISA). (2025). ENISA Threat Landscape 2025.
[2] Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2024). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST SP 800-161 Rev. 1, Update 1.
[3] European Parliament and Council. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2).
[4] Reichert, B. M., & Obelheiro, R. R. (2024). Software supply chain security: a systematic literature review. International Journal of Computers and Applications, 46(10), 853–867.
[5] Cybersecurity and Infrastructure Security Agency (CISA). (2024). Securing the Software Supply Chain: Recommended Practices for Software Bill of Materials Consumption.
[6] Gokkaya, B., Aniello, L., & Halak, B. (2023). Software supply chain: review of attacks, risk assessment strategies and security controls.
[7] Ladisa, P., Ponta, S. E., Sabetta, A., Martinez, M., & Barais, O. (2023). Journey to the Center of Software Supply Chain Attacks.
[8] National Institute of Standards and Technology. (2026). Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start Guide. NIST SP 1326.
[9] ENISA. (2023). Good Practices for Supply Chain Cybersecurity.
[10] Shourya, R., Kumagai, Y., Ashokkumar, C., Yamazaki, H., & Nakakoji, H. (2023). Proposal of Vulnerability Assessment Tool for Software Supply Chain Security. Journal of Information Processing, 31, 842–850.
Published
Issue
Section
License
Copyright (c) 2026 Петя Петрова

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Articles published in "Computer Science and Communications" Magazine are licensed under Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.