How should supply-chain and trusted-service incidents be reported?¶
Supply-chain and trusted-service incidents should be reported by separating trust relationship, delivery mechanism, execution, impact and attribution.
Evidential caution: that naming the supplier explains who caused the incident.
What this means¶
A defensible report should identify:
the supplier, service or dependency;
the trust relationship;
the affected account, update or component;
how the activity reached the target;
which systems received it;
which systems executed it;
what impact followed;
whether the supplier was compromised, negligent or knowingly involved;
what personal attribution is supported.
“The signed update executed malicious code” is different from “the vendor knowingly distributed malware.”
“The management platform deployed the script” is different from “the provider employee authorised it.”
“The cloud service hosted the payload” is different from “the provider controlled the attack.”
Explain shared services, resellers, compromised accounts and incomplete provider records.
Also identify whether trust was technical, contractual, organisational or all three. A signed package, provider account and established supplier relationship may each influence why the activity was accepted. Those trust mechanisms should be described separately from the offender’s method of abusing them.
Where the supplier provides conclusions about root cause or affected scope, distinguish their technical findings from the customer’s own evidence. The final report should state which conclusions are independently corroborated and which rely on provider assessment.
State that dependency clearly in the assessment.
State that dependency clearly and precisely in the final assessment. The operational takeaway is:
Report the trusted relationship, delivery, execution, impact and attribution as separate findings, and do not convert supplier involvement into automatic offender responsibility.
================================================================================
What to check or do next¶
- Use precise language.
Evidential limits¶
It does not.