The purpose of secure SCRM is to identify and mitigate any risksin the software supply chain. Please prepare a response to thefollowing items: You have to identify every component andmanufacturer in your supply chain (through the acquisition process)there has to be a company for every component. You do that byfunctional decomposition of the product into the lowest level ofcomponent – a component tree – trunk = the product – the leaves =the lowest level in the supply chain – this is your roadmap forcontrol of the process For this first exercise you will define thepotential functions required as well as who will supply them. Youwill take the following steps: THIS IS ALL CREATIVE WRITING FROMTHE CASE
1 Identify a process in the case that you intend to support by asoftware application – this should include a scope, business caseand assurance case statement You have a single product or processidentified for an RFP
2 Define top-level functions required to carry out the desiredprocess – these must be coherent (e.g., logically related andcomplete) - what you would have to do, or create in order to meetthe requirements of what you intend to supply (make the thing) –this is a function of design – think about this in terms of all ofthe steps in the process and products of those steps what are theparts and how will they be assembled? This is abstract needs to bevisualized in concrete terms
3 Decompose the top-level functions into a second level ofcomponent functions
4 Decompose the second level functions into a third level ofcomponent functions (e.g., formulate a component tree) – this is abasic planning/design process where you think about the sources ofthe things you are going to use… decomposed to the lowest level inthe process hierarchy – you will hand me a decomposed list ofmaterials and suppliers to address the function you problem you aregoing to solve by your purchase
5 Assign a (imaginary) supplier for each component at alltiers – these will be assumed to be subcontracted relationships(e.g., the work will be done by a subcontractor directly employedby the higher-level entity) – normally the components at the nextlevel – or at all levels – will be contracted based on thespecifications/criteria you set… give me three contract criteria –what will it take to satisfy the requirements for that particularcomponent /part of the overall product? How will you decided youhave the right supplier – the security criteria have to be explicitfor every element of the supply chain (how will you assure this?This is the plan)
The purpose of secure SCRM is to identify and mitigate any risks in the software supply chain. Please prepare a response
-
- Site Admin
- Posts: 899603
- Joined: Mon Aug 02, 2021 8:13 am