科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Applied Cybersecurity & Internet Governance2025-12-05· Supply chain

Supply Chain Security and AI Risk Governance Model for Critical Infrastructure under NIS2, CER, and CRA

Natalija Parlov, Gordan Akrap, Josip Esterhajer

原始摘要(英文原文)· Original abstract
Critical infrastructure increasingly depends on digital ecosystems where external providers, artificial intelligence (AI)-based tools, and complex supply chains form the backbone of essential services. This interconnectedness generates cascading risks that surpass the scope of internal controls, exposing sectors, such as energy, water, food, healthcare, and transport to systemic vulnerabilities. Known incidents illustrate that supply chain compromise is not a theoretical possibility but persistent and growing reality. According to the authors’ practical experience in national security and sectoral information security, cybersecurity and resilience-oriented projects, organisations often struggle to recognise context of the threats in their critical services, wideness, and vulnerabilities of own supply chain and/or translate standards and new regulatory requirements into daily operational measures, which is a gap this model seeks to address. The purpose of this paper is to underline why supply chain and AI-related risks represent a systemic challenge for critical infrastructure, demonstrate how existing standards and regulatory frameworks can be synthesised into a coherent governance model and provide organisations with a practical tool that moves towards operational resilience. The chosen methodology rests on comparative analysis of chosen international standards (ISO 28000, ISO 31000, ISO/IEC 27001/27002/27005, ISO/IEC 23894, ISO/IEC 42001, and NIST AI RMF), supported by European Union obligations and recent European Union Agency for Cybersecurity [European Network and Information Security Agency] (ENISA) recommendations. Five-step supply chain security and AI risk governance model contribute structured, practical step-by-step model for strengthening systemic resilience. As an immediate step, operators should insert at least one supply chain-specific clause into their next procurement or renewal contract: a clear timeline and format for incident notification by the supplier.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Supply Chain Security and AI Risk Governance Model for Critical Infrastructure under NIS2, CER, and CRA — 科研速览 Science Skim