Skip to main navigation Skip to search Skip to main content

A Reference Model for Information Security of Information and Communication Technology Product Supply Chain

  • Liangyu Dong
  • , Sheng Hong*
  • , Jianing Zhao
  • , Jiacheng Wang
  • , Yang Li*
  • *Corresponding author for this work
  • Response Team
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Information and Communication Technology (ICT) products are becoming increasingly important in people's daily lives, and cyberspace security issues caused by ICT supply chains have attracted widespread attention. This paper reflects that, even while various contributions were made towards the construction of information security frameworks, there appears still to be an absence of an explicit reference model. The choice of research subject here is ICT supply chains, in which a reference security model framework for cyberspace security of ICT supply chains is discussed. The reference model developed is based on the application of the NIST information security reference model methodology. Conducting a thorough analysis of ICT supply chain structure and information security risk, we categorize the various kinds of information security attacks on ICT supply chain and catalog them on the security target reference model. This developed model of reference information security shall serve as an excellent articulation of how to boost the confidentiality, integrity, and availability of systems design, analysis, and verification to specific attack types through hacking. Therefore, the research methodology described herein is equally appropriate and transferrable for the information security studies of other information systems. Hence, the reference model framework proposed in this research may play an important role in fields related to information security and may promote the development of effective countermeasures against ICT supply chain attacks.

Original languageEnglish
Title of host publicationProceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages109-114
Number of pages6
ISBN (Electronic)9798331535858
DOIs
StatePublished - 2025
Event3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025 - Dongguan, China
Duration: 11 Apr 202514 Apr 2025

Publication series

NameProceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025

Conference

Conference3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
Country/TerritoryChina
CityDongguan
Period11/04/2514/04/25

Keywords

  • Information Security
  • Information and Communication Technology
  • Security Reference Model
  • Supply Chain security

Fingerprint

Dive into the research topics of 'A Reference Model for Information Security of Information and Communication Technology Product Supply Chain'. Together they form a unique fingerprint.

Cite this