White House looks to revamp cyber supply chain security data calls | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The federal CIO’s office is reviewing governmentwide cyber supply chain security standards, as it looks to root risks related to foreign adversaries.

The White House is reviewing how agencies report on their cyber supply chain security programs, with new metrics expected in the “near term” to get a better picture of shared risks, especially those related to foreign adversaries.

The White House Office of the Federal Chief Information Officer has been tasked with reviewing how agencies align with National Institute for Standards and Technology guidelines on “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.”

Those standards provide guidance on evaluating risks associated with products and services “that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain,” according to NIST.

Cheri Benedict, senior cyber supply chain advisor within the federal CIO’s office, said governmentwide compliance mechanisms for those NIST standards are due for an upgrade. They were last updated in the wake of the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure (SECURE) Technology Act of 2018.

“We are now reviewing all practices and procedures as it relates to that to then inform the way forward,” Benedict said during a Tuesday webinar hosted by the Intelligence and National Security Alliance. “And in in the near future, agencies can expect a revamp of that data collection that tries to capture the status and perspective of maturity of their program, and moreover, not just that, but really helps us realize how we can better partner to move forward in common against threats.”

Benedict said the ongoing review of governmentwide standards is emphasizing “the sharing perspective and the perspective of shared risk.”

“There are many different risks, and we want all of it to be brought to bear if there’s a desire and shared perspective, but we especially focus on adversarial related risk, and that can take different forms and fashions,” she added. “But that is something that we want to prioritize as a federal government.”

The SECURE Technology Act of 2018 established the Federal Acquisition Security Council as an interagency body responsible for identifying supply chain risk management standards and guidelines. The council can also provide recommendations on issuing orders for excluding and removing vendors from government supply chains.

Last September, nearly seven years after the law’s passage, the Director of National Intelligence adopted a recommendation from the council to issue the first such removal and exclusion order against Acronis AG, a Switzerland-based technology firm. The order applies to intelligence community procurements and sensitive compartmented information systems.

House lawmakers on the Select Committee on China have proposed bipartisan legislation to update the FASC, including by moving it into the Executive Office of the President and providing it with dedicated staff to monitor high-risk foreign vendors and equipment across government.

Meanwhile, Benedict pointed to the Trump administration’s 2026 national cybersecurity strategy and its goal to “move away from adversary vendors and products, promoting and employing U.S. technologies.”

She said officials want to move to “left of boom” in supply chain security, where risky vendors and products are identified and excluded before they are embedded in U.S. government systems.

“That means that we have to do secure supply chain reviews even before award,” Benedict said. “And I know it’s tough. We already have such prolonged acquisition timelines, but to the extent that we are able to, especially for our high priority assets to be able to really secure better, we need to get left of boom and really be able to see deeper into our supply chain landscape, especially in the advent of AI.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.