Anyone ever implemented a supply chain risk management program? How? What steps did you take?

like
Posting as :
works at
You are currently posting as works at

Have you read 800-161? If not, start there. I always start with NIST

like

Not exactly, but I have assessed multiple Supply Chain Risk Management Programs. I would start by leveraging your Configuration Management program and process and conduct a gap analysis between current and future state. Identifying your future state isn’t going to be easy but NIST CSF and the SR controls in NIST 800-53 R5 are a good place to start. After you identify your gaps and target state, build out robust policies,procedures, and processes that integrate well into your current organizational processes such as CM. Some of the biggest hurdles will be updating your shipping and receiving process to account for the updated requirements and working with your engineers to validate existing components/products/vendors. Overall, you are looking at a 8-12 month effort.

like

It’s almost as if you need a consultant.

funny

Yeah ask ChatGPT. Big 4 will charge you 💵 to answer your questions.

funny

Related Posts

Best thing a leader has done for you?

like

Larsen & Toubro Infotech How is EY Global Services Project in LTI?
Larsen & Toubro Infotech

like

Thinking of an affordable brown leather automatic watch. Thoughts on shinola runwell automatic? Any alternatives you would recommend?

like

Does anyone have a LV watch roll? Worth it? Open to their similarly priced options (~$1k).

Post Photo
likefunny

Has anyone had experience working with their AD to help procure watches from brands the dealer doesn't carry?

like

Hi all, I am looking for a job role in sales/business development manager for Gujarat, India location. Please let me know if any...

like

I just had my 3 month performance evaluation. It went really well and I received a raise, but I’m worried if I should of negotiated it. It went from $41K to $45K. Is this reasonable? I’m considering I’ve been in the field for only 3 months.

like

Anyone from ACN asked to take a week of vacation in June? I was asked to but the friends I checked with we’re not; afraid I’m being prepped to exit.

like

How unlimited PTO feels

Post Photo
likefunny

Ready for his close up

Post Photo
like

While you still can...

Post Photo
likefunny

DFW area - when will the rain stopppppp?

Post Photo
like

Anyone else love the movie Carnage? I feel like the lawyer (Waltz) and investment banker (Winslett) are so accurate to the personalities that you meet in our strange world.

likefunny

I only have limited time in Copenhagen, and can only choose between Glyptoteket or National Gallery of Denmark. Which one would you recommend and why?

like

can i get 11 hearts to post in other bowls

like

Is it too late to get biontech stock? Seems like we are going to get vaccines for Covid on a regular basis?

like

Am I crazy for thinking the next ten years look bearish for mega-cap tech? Explanations inside.

like

Additional Posts in Cyber Security Bowl

Any Penn Testers in the U.S looking for freelance work? Please dm

like

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like

I need to design a Cybersecurity logo for an internal team. They don’t want to use images of a shield🛡 or lock 🔒 . What other icons do you guys think represent “Cybersecurity”. I’m not a creative

like

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

Any tips or tricks for CSX certification?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Stay and maybe get promoted to manager in august (been with firm 18 months) or leave to a boutique and make 30% more + RSUs? Would go to a boutique publicly traded firm like mandiant or Crowdstrike - Have an in at both. Currently at 130k

like

Anyone here make it out of IT audit to a more interesting role?@

funnylike

How long does Deloitte take to issue an offer. I interview for a DevSecOps position and was told I was getting an offer extended to me. I have barely heard back in almost 2 weeks from anyone about the offer and need to make a decision on other offers. What do I do? Could they be rescinding my offer?

like

Today I passed CIPP/US, and earned Security+ in early August. Interviewing for a cybersecurity role at Deloitte tomorrow! Super excited! Interested to connect with fish at Deloitte, especially Deloitte Global. Thanks!

like

Tell me it’s not true.

Post Photo
funnylike
like

At what point do you walk away when bosses or team values do not align with your personal values? Boss told me I’m too soft and I should be prepared to burn bridges if it’s a good outcome for company.

Salary range for principal consultant at Discover Financial Services?

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

Worth making a jump to BCG Platinion from ACN? Information is sparse in my research. Opinions appreciated.

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Looking to break into industry from federal consulting. Recently earned my MBA with a focus on data analytics and MS in Cybersecurity. Any guidance?

like

For those who have passed the CIPM exam, what is it like (and how does it compare to the CIPP/US exam)?

Anyone currently enrolled or will be enrolled in the online masters cyber degree at Georgia Tech?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal