|
|
By Gabriela Barragan
|
The ERO Enterprise has identified supply chain as a risk element within the 2026 Compliance Monitoring and Enforcement Program (CMEP) Implementation Plan (IP), largely due to the ongoing reliability concerns involving malicious software insertion. CIP-010-4 R1, Part 1.6 requires Responsible Entities to implement software verification controls, including identity verification software sources and the integrity of software obtained prior to implementing any baseline change associated with operating systems, firmware, commercially available software, open-source software, and security patches.
While Responsible Entities should implement operational safeguards tailored to their environment, industry best practices for CIP-010-4 R1, Part 1.6 include:
For more information and further guidance on implementing best practices related to supply chain, Texas RE encourages Responsible Entities to consult the Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.