A system is only as strong as its weakest part — a dictum that applies to IT systems as well as any other. The government’s buyers at the General Services Administration want to make sure weaknesses aren’t creeping in through the hardware and software purchased by agencies and is looking for ways to monitor the supply chain from end to end.
GSA issued a request for information on May 9 for a Supply Chain Risk Management Provenance Pilot Program with the end goal of developing a contract solution to protect federal systems “from possible spying, cyberattack and tampering by implementing supply-chain risk management systems.”
RFI: Supply Chain Risk Management Provenance Pilot
The problem occurs when vendors somewhere in the supply chain — either unbeknownst to others or with their tacit agreement — use third-party, out-of-date or otherwise subpar components to pad their bottom line. These components can introduce security flaws, either by being underdeveloped or including “greyware” software.
“Middlemen seeking to exploit price differences in different geographic regions typically import grey market goods,” according to the RFI. “Many take advantage of consumer who do not realize or appreciate the differences between the goods.”
The pilot and RFI are looking at commercial solutions to the problem that would “validate the authenticity of commercial IT products and software” from beginning to end.
Rather than assessing every physical system individually, GSA is hoping to find a solution “through which the federal government monitors performance metrics and that allows management through roles and business rules rather than physical control of assets and direct software licensing.”
The RFI asks companies what solutions they use to ensure their supply chains aren’t corrupted, whether it’s a product they sell or just one they use internally. Along with other logistics, GSA is interested in figuring out what the appropriate acquisition model is for this type of service.
“If possible, please provide a rough order of magnitude pricing,” one question asks. “Can the customer pay for services as utilized — pay by the drink — or must the customer fund an entire system ‘up front’ to gain any benefits from the contractor’s offering?”
Responses are due by 5 p.m. May 31. Any questions should be submitted to GSA by noon on May 16.




