Procurement and Cybersecurity
Enhancing Confidence
Introductions
Nice to meet everyone
Our consultancy aims to help public and private entities understand how policy impacts their technology (and vice versa) through process modeling, data analysis, and policy research.
Selected works
Our team
President�Jared Marcotte
VP of Operations �Nancy Khuu
Research Lead�Grace Gordon
Operations Research Scientist�Dr. James Houghton
Senior Solutions Architect �John Dziurłaj
Solutions Architect �Brian Guayante
Analyst�Tifawni Haynes�
The state of things
The good and the bad
https://learn.cisecurity.org/NCSR-2022-Summary-Report
https://verizon.com/dbir/
High stakes require high standards
…but how to make sense of it all?
It takes a village
“Procurement teams, IT teams and IT security teams all have a role to play in making successful IT deployments possible.”
Recommendations
No shortage of information
Center for Internet Security’s RABET-V program
A case study in product verification
2019 Development begins
2020 First pilot
2021 Program development
2022 Second pilot
2023 Program launches
Steering Committee: Representatives from Indiana, Maryland, Ohio, Pennsylvania, Texas, Wisconsin, EAC, CISA, NASED, and FVAP
Technical Advisory Committee: Representatives from CIS, NIST, Carnegie Mellon University, OWASP, Akamai, and the Atlantic Council
https://www.cisecurity.org/elections/rabetv
Understanding RABET-V
Fundamentals and objectives
Testing to meet modern software development
How does RABET-V differ from other programs?
The RABET-V process
Who tests: independent accredited assessors
Organizational Assessment
Architecture Assessment
Product Verification
10 Security Control Families
Reporting
Technology Providers
Officials
Public Listing Site
Very detailed reports
Very detailed reports
Architectural Maturity
Product Testing Maturity
Streamlined testing of changes
Incorporating RABET-V
Utilizing procurement frameworks
Program benefits
Benefits to jurisdictions
Benefits to tech providers
State and locality support
Success stories
Managing procurement risks
Considerations into existing procurement processes
Point-in-time testing isn’t enough
Strengthening management
And relationships
Managing supply chain risks
Criteria for assessing vendors
Do they pass the baseline?
RABET-V Module | 2024 Baseline | Tested Product | Meets Baseline |
Organization | 1.20 | 1.42 | Yes |
Architecture | 1.50 | 1.90 | Yes |
Product | 2.00�Level 1: 100%, Level 2/3: 50% | 2.32�Level 1: 100%, Level 2/3: 74% | Yes |
�
Product Verification scoring consists of an overall score, the percentage of Level 1 requirements met—which must be 100%—and percentage of Level 2/3 requirements—which must be greater than 50%.
Building collaborative relationships with vendors for enhanced cybersecurity
Enhancing accountability and performance through continuous evaluation
Speed is of the essence
Empowering procurement teams
With knowledge and tools
Next steps
To conclude
Final thoughts
Thank you
Happy to take questions