Search NASA⌕ Search

SEARCH · Search NASA

Results for “third-party risk management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

System-Level Integration of Modular Language Models for Real-Time Risk Assessment in Third-Party Risk Management Systems

Large enterprises typically rely on dedicated teams to govern and implement security measures throughout their supply chains, ensuring compliance with enterprise security procedures. There is a significant reliance on Third-Party Risk Management (TPRM) platforms, which often require complete, highly structured information from potential vendors. The review and compliance assurance processes are time- and labor intensive, often requiring several rounds of review between the supply chain security risk management teams, business users, and potential vendors, leading to delays in the supply chain processing and consumer experience. Significant challenges in the risk management paradigm include handling unstructured data in various formats and providing real-time feedback to users to reduce the required review time. This paper presents a novel solution to these challenges. A modular multi-step system architecture is proposed using advances in language processing, specifically for unstructured responses and provides real-time feedback (i.e., 3 seconds) so that users can improve their responses before the TPSRM team review. This novel system architecture will increase information accuracy and significantly reduce time and labor during the review process.

99 - GENERAL AND MISCELLANEOUS↗

Third-Party Supplier Risk Re-Classification Using Multi-Model Semantic Voting and External Web Augmentation

Risk decisions in many third-party risk management (TPRM) workflows rely on static inherent risk questionnaires (IRQ). These static forms provide a snapshot of the vendor from the business users’ perspective, as these requests are processed without cross-referencing for evidence. Consequently, responses can be misinformed or embellished with inaccuracies, thereby masking the vendor’s true risk to the enterprise. This paper presents a multi-stage verification framework to augment IRQs with web evidence and a deterministic ensemble of large language model assessors to reclassify risk. In a case study of 100 submissions previously misclassified as low risk, the proposed framework correctly identified 76% of the cases as high risk, while the existing workflow identified none. McNemar’s continuity corrected statistics of 74 were obtained with a two sided p-value of 2.65 × 10-23, indicating a significantly more effective workflow compared to the legacy model.

99 - GENERAL AND MISCELLANEOUS↗

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Modernizing the Legacy Fission Wire Measurement System for the Advanced Test Reactor-Critical Facility

Operational lifetime extensions of existing research reactors have emphasized the need for refurbishment, replacements, and upgrades to supporting equipment and instrumentation. The Advanced Test Reactor (ATR) at Idaho National Laboratory (INL), which entered service in 1967, has recently completed the sixth core internals change-out and has scheduled operations until at least 2040. Reactor maintenance and operational risk management is critically important in the research reactor community, however supporting measurement systems sometimes get overlooked when maintenance is planned. The Fission Wire Measurement System (FWMS) is a custom measurement system designed in the 1960s to measure the beta-particle activity of irradiated uranium-aluminum fission wires. This measurement is conducted to determine the fission rate profile of the Advanced Reactor Test Critical (ATR-C) facility. The ATR-C is an open-pool, low-power test reactor that was purpose driven to resemble ATR and is used to qualify experiment configurations and verify core models prior to full-power experiment irradiations in ATR. A power distribution measurement in ATR-C uses uranium-aluminum wires that are distributed throughout the ATR-C core to validate simulation and modeling results. These measurements require 340 to 1500 wires to be irradiated and measured within a 12-hour window. The activity of the wires is measured in the required time with the FWMS, which was put into service in 1965 at the Radiation Measurements Laboratory (RML). The system consists of 4 measurement channels and one reference channel, each with a 2-pi proportional gas flow detector and the measurement channels each have an automated sample changer. This legacy system is crucial to the continued operations of ATR and has undergone some minor hardware upgrades since 1965, however the system presently relies on custom control boards, custom gas ion chambers, analog amplifiers/discriminators, and a user interface (UI) for the system written in outdated code. Much of the equipment and software is custom with no commercial replacements or support and limited documentation. The existing control software requires an operating system that is no longer supported, creating more vulnerabilities to continued operations. A project is underway with a third-party vendor to design, build, and document a new control and data acquisition system (CDAS) for the FWMS. The new upgrade will replace the control system, computer, UI, sample changer motors, and main power supply while maintaining the interface with existing detector hardware. The upgraded system will be operated in parallel with the current hardware and software to conduct validation testing. This equipment upgrade demonstrates the commitment at ATR to ensuring successful operations and potential future research reactors at INL.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗