Executive Order Aims to Protect Defense Supply Chains
President Donald Trump has signed an executive order requiring the Department of War to develop new rules for mapping and securing critical defense supply chains, including the software, services, and technology used in national security systems.
The order states that the United States must protect its defense supply chains against “physical, cyber, and economic subversion,” and calls for greater visibility into suppliers and subcontractors at every tier.
Mapping Critical Supply Chains
Within 180 days, the Secretary of War must develop policies requiring defense contractors to map critical supply chains supporting national security acquisitions.
Implementing regulations are due within 90 days after the policies are completed. The requirements would apply not only to prime contractors but potentially to subcontractors at every level of the defense supply chain.
Software Included in Supply Chain Mapping
Under the proposed regulations, contractors would be required to submit a complete “indentured Bill of Materials” tracing components, equipment, software, and materials through the supply chain and back to the origin of the underlying raw materials.
The contemplated documentation is significantly broader than a traditional software bill of materials, or SBOM. It could connect software and firmware dependencies with physical components, manufacturers, suppliers, maintenance information, countries of origin, and raw-material sources.
Contractors Required to Vet Suppliers
Contractors would also be required to establish written procedures for proactively vetting suppliers and subcontractors. At a minimum, the reviews must consider financial stability, foreign ownership or influence, and manufacturing and supply risks.
Contractors would be expected to identify concerns such as sole-source dependencies, inadequate production capacity, supplier concentration, and overreliance on a single source.
Supply Chain Risks Must Be Reported
After completing the required vetting, contractors would have to mitigate identified risks and track corrective actions until closure. Significant supply chain risks would need to be reported to the Department of War within 15 days after the vetting activities are completed.
Contractors would then have 45 days to submit a confidential corrective action plan detailing their mitigations and a timeline for completing the work. A closeout report would also be required after corrective actions have been implemented.
Sensitive Supply Chain Data Could Become a Target
The comprehensive supply chain maps required by the order could themselves create significant cybersecurity risks. A detailed database connecting defense systems to software dependencies, suppliers, raw materials, manufacturing locations, and operational bottlenecks would provide a potentially valuable target for foreign intelligence services and other threat actors.
Compromised supply chain data could help an adversary identify single points of failure, difficult-to-replace suppliers, vulnerable software dependencies, and opportunities for espionage, sabotage, or economic coercion.
Government to Use AI for Supply Chain Analysis
The order directs the Department of War to use available tools and technologies, including artificial intelligence, to analyze contractor acquisition information and identify national security vulnerabilities, bottlenecks, and single points of failure.
The AI provision could allow the government to analyze extremely large and complex networks of suppliers, components, and dependencies. However, it may also raise questions about the accuracy of supplier-risk determinations, the protection of proprietary information, and the security of centralized government supply chain databases.
Source: SecurityWeek