Vendor library offers means to bolster supply-chain security through data sharing and communication. Credit: Anna Jiménez Calaf A new library designed to be a centralized source of security information and communication for energy company suppliers was announced Tuesday by Fortress Information Security. The Asset to Vendor Library Trust Center is a project of Fortress, American Electric Power and Southern Company, and offers a way for suppliers to connect with their customers and provide information about their supply chain security practices.The library is a supplier-centered marketplace with the ability to share and update cybersecurity information, as well as provide marketing materials for patrons. Vendors and original equipment manufacturers can control the information they provide their customers, such as security attestations, completed North American Transmission Forum questionnaires, and third-party certifications.Suppliers can choose how to share their information in the librarySuppliers can choose to share information with everyone in the library or limit access to members who request it. Giving suppliers control over access to their information helps them solve the challenge many suppliers experience of receiving and exchanging security controls questionnaires from multiple prospects or clients. Each is phrased slightly differently but all are essentially the same.“A lot of these vendors only play in this market,” explains Betsy Soehren Jones, COO of Fortress, a provider of cyber risk management solutions for supply chains. “They’re frustrated with having to fill out 3,000 copies of the same form and sending it to all their customers.” She added that the library is designed with security in mind. “All the transactions in the library are encrypted,” Jones says. “Information flowing from the vendor and requests from customers to the vendor are done in a secure and protected manner.”“There are no analytics happening in the library itself,” Jones says. “Once a customer requests something from the library, that transaction goes away. So, there are no records of who is using what part or where a part is installed. It would take an enormous amount of work to use the material in the library for malicious purposes.” Information from 40,000 companies in the libraryCapabilities the Trust Center provides users include:Compliance management and audit preparation questionnaires and surveys patterned to meet existing and emerging regulatory standardsData-driven risk ranking that employs AI and open-source intelligence to determine the criticality and cyber maturity of supplier assetsSupplier validated product assessments that provide visibility on vulnerabilities, patch history, and security controlsInsights into the geopolitical relationships of suppliers, their products, and their fourth-party suppliersPatented blockchain technology for securely sharing software and hardware bills of materials and analyses designed to uncover open-source vulnerabilities, product components, and geopolitical affiliationsContinuous monitoring of all active suppliers, their customers, and fourth party vendorsSome 40,000 companies have submitted information to the library, but more information is needed. “The Trust Center and Fortress are positioned to help the industry educate the vendor community on why this is needed and have them deposit their answers in the Trust Center,” Jones says. “In the meantime, we understand that utility companies need to make business decisions, so what we will be doing in the interim is provide them with a data-driven reports compiled from open-source sources.” Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe