{"id":20993,"date":"2018-08-24T19:37:56","date_gmt":"2018-08-24T19:37:56","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/"},"modified":"2026-08-08T04:53:59","modified_gmt":"2026-08-08T04:53:59","slug":"voluntary-doesnt-secure-the-supply-chain","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/","title":{"rendered":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><i>This is part three in a multipart series on supply chain security. Click here for <\/i><a href=\"https:\/\/www.federaltimes.com\/opinions\/2018\/08\/13\/federal-supply-chain-threats-quietly-growing\/\"><i>part one<\/i><\/a><i> and <\/i><a href=\"https:\/\/www.federaltimes.com\/opinions\/2018\/08\/16\/when-fisma-isnt-enough\/\"><i>part two<\/i><\/a><i>.<\/i><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The federal government encourages many forms of voluntary security measures. The National Institute of Standards and Technology has produced a voluntary cybersecurity framework that is a useful way to organize, achieve and measure security progress. But voluntary measures are insufficient when not everyone is adopting the measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adversaries can and will exploit resulting gaps and wreak widespread injury through supply chain attacks directed against weak links, such as market participants indifferent to security. This exposure, unfortunately, also is present in the Department of Defense\u2019s efforts to improve the cybersecurity of defense industrial base contractors. There, NIST Special Publication 800-171 safeguards are specified \u2014 but there is no method of assurance or assessment beyond \u201ctrust\u201d in contractors to comply with contract terms. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An unfortunate truth about supply chain vulnerability \u2014 and especially software supply chain exposure \u2014 is the enormous attack surface and the virtually limitless number of points where an attack can be executed. Adversaries can avoid the best defended resources and most secure products (or components) and instead find weak actors and exploit insecure entry points. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Procurement measures are significant. but not sufficient<\/b> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DoD has been the leader in efforts to defend against supply chain exposure. Even so, experience shows that procurement methods may not achieve effective supply chain security across the entire range of exposure. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By definition, procurement measures, such as federal acquisition regulations or contract clauses, affect only those in the chain-of-contract with the federal agency customer. While the universe of companies affected by DoD procurement measures is significant, it nonetheless represents a very small fraction of U.S. enterprises at risk. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even where procurement methods matter, such as in DoD procurements and those of other federal agencies, today\u2019s emphasis is on price, schedule and performance. Security requirements may be tacked on to new solicitations for supplies and services, but federal purchasers, at present, evaluate the cyber and supply chain security of contractors only in limited instances. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Federal leaders should elevate security to the point that it becomes the \u201cfourth pillar\u201d of the acquisition process \u2013 equal in priority to cost, schedule and performance. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Software supply chain attacks: discrete targets, broad effects<\/b>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conventional thinking has been that adversaries seek high \u201creturn on investment\u201d by targeting supply chain attacks in ways that achieve precise, impactful effects. The publicly reported experience with Kaspersky Labs software, however, suggests an alternative paradigm that is very dangerous: infiltration through widely installed, publicly accessible software. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Measures confined to government contractors, or which are voluntary for commercial enterprises, do little to mitigate and certainly do not defeat such threats. Commercial sources of supplies or services for government use can be unwittingly exposed to tainted, commercial-origin, widely marketed software and, conceivably, firmware in widely utilized devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No part of the \u201csystem development life cycle\u201d is unexposed to software-delivered supply chain attack. Contemporary systems typically depend upon a global supply chain for parts and for software, including open-source components from sources both known and unknown. There is exposure at all points along the life cycle spectrum, from inception to end-of-life disposition. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even industrial base issues come into play here, as the U.S. becomes increasingly dependent upon foreign sources for critical, high-performance microelectronics. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>IoT: Internet of Threats<\/b> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet of Things is producing massive interconnection of sensors, devices and systems \u2013 and massive interdependencies among systems. Literally billions of connected devices are in our near-term future. With this connectivity, paths for attack, malware propagation and distribution grow exponentially. Detection and response to such attacks implicates many federal agencies, notably the FCC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FCC has a pivotal role in security of our increasingly interconnected national economy. It is the \u201cgatekeeper\u201d for the communications instrumentalities upon which connected systems rely in private sector and for much of the public sector. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apart from authority to hold regulated communications service providers to higher security standards, the FCC can play an important role in shaping future network architecture so that transport layer attacks are rapidly identified and isolated \u2014 helping to mitigate the risk of \u201ccascading\u201d impacts across connected systems. The FCC will also have a key role in protecting U.S. interests in the development of the 5G mobile networks standard, where other nation-states may seek outcomes adverse to the U.S.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Robert Metzger is a shareholder of the law firm of Rogers, Joseph O\u2019Donnell, PC and head of the firm\u2019s office in Washington, D.C. As a special government employee of the Department of Defense, he was a member of the Defense Science Board (DSB) Task Force that produced the Cyber Supply Chain Report in 2017. He is active in other public-private initiatives, including cyber and supply chain security work for the MITRE Corporation.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Government contracting poses inherent supply chain threats. One agency can make a difference, but it&#8217;s not who you think.<\/p>\n","protected":false},"author":7,"featured_media":39896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":26,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,31,33,26],"tags":[],"coauthors":[2744],"class_list":["post-20993","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters","category-opinions"],"acf":{"subheadline":"","legacy_arc_id":"VTSFEBXDQBFDDGLLGSMSC6DC6Q","arc_canonical_url":"\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u2018Voluntary\u2019 doesn\u2019t secure the supply chain - Federal Times<\/title>\n<meta name=\"description\" content=\"Government contracting poses inherent supply chain threats. One agency can make a difference, but it&#039;s not who you think.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain\" \/>\n<meta property=\"og:description\" content=\"Government contracting poses inherent supply chain threats. One agency can make a difference, but it&#039;s not who you think.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-24T19:37:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T04:53:59+00:00\" \/>\n<meta name=\"author\" content=\"Robert Metzger\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Robert Metzger\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain\",\n\t            \"datePublished\": \"2018-08-24T19:37:56+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:53:59+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/\"\n\t            },\n\t            \"wordCount\": 799,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635924283160512126-computer-hardwarejpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/\",\n\t            \"name\": \"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635924283160512126-computer-hardwarejpg.jpg\",\n\t            \"datePublished\": \"2018-08-24T19:37:56+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:53:59+00:00\",\n\t            \"description\": \"Government contracting poses inherent supply chain threats. One agency can make a difference, but it's not who you think.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635924283160512126-computer-hardwarejpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635924283160512126-computer-hardwarejpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2018\\\/08\\\/24\\\/voluntary-doesnt-secure-the-supply-chain\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/\",\n\t                    \"ad_zone\": \"opinions\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain - Federal Times","description":"Government contracting poses inherent supply chain threats. One agency can make a difference, but it's not who you think.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain","og_description":"Government contracting poses inherent supply chain threats. One agency can make a difference, but it's not who you think.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/","og_site_name":"Federal Times","article_published_time":"2018-08-24T19:37:56+00:00","article_modified_time":"2026-08-08T04:53:59+00:00","author":"Robert Metzger","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Robert Metzger","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain","datePublished":"2018-08-24T19:37:56+00:00","dateModified":"2026-08-08T04:53:59+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/"},"wordCount":799,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635924283160512126-computer-hardwarejpg.jpg","articleSection":["Daily Brief","Home","Newsletters","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/","name":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635924283160512126-computer-hardwarejpg.jpg","datePublished":"2018-08-24T19:37:56+00:00","dateModified":"2026-08-08T04:53:59+00:00","description":"Government contracting poses inherent supply chain threats. One agency can make a difference, but it's not who you think.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635924283160512126-computer-hardwarejpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635924283160512126-computer-hardwarejpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2018\/08\/24\/voluntary-doesnt-secure-the-supply-chain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/","ad_zone":"opinions"},{"@type":"ListItem","position":3,"name":"\u2018Voluntary\u2019 doesn\u2019t secure the supply chain"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635924283160512126-computer-hardwarejpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/20993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=20993"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/20993\/revisions"}],"predecessor-version":[{"id":20995,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/20993\/revisions\/20995"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=20993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=20993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=20993"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=20993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}