• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » What Constitutes ‘Critical’ Software in Biden’s Executive Order on Cybersecurity?

Think Tank
Think Tank RSS FeedRSS

What Constitutes ‘Critical’ Software in Biden’s Executive Order on Cybersecurity?

Network Cables
Computer network data cables. Photo: Bloomberg.
July 26, 2021
Robert J. Bowman, SupplyChainBrain

At the direction of President Biden, the National Institute of Standards and Technology recently issued an updated definition of what constitutes “critical” software components that are commonly found within supply chains. But according to one cybersecurity expert, the language reveals a curious omission.

In proposing which aspects of cybersecurity technology should be included in the initial implementation phase of the Administration’s executive order to review and secure the nation’s critical supply chains, NIST excludes embedded software and firmware components, notes Eric Greenwald, general counsel with Finite State, a provider of connected device security systems.

Acknowledging that such components are often “critical” to securing I.T. systems, NIST nevertheless suggests that they’re too complex in nature to be included in the early implementation phase of the Administration’s efforts.

NIST says it coordinated its definition with input from numerous other agencies, including the Cybersecurity & Infrastructure Security Agency (CISA), Office of Management and Budget, Office of the Director of National Intelligence, and National Security Agency. CISA, part of the Department of Homeland Security, will draw on NIST’s finding to devise its own list of software categories that fall under the scope of the first phase of the review.

NIST’s claim that embedded software and firmware — the basic, low-level controls for device hardware — are too complex to be taken up immediately is contained in an answer to “frequently asked questions.” But Greenwald says he’s puzzled by the brief statement.

“I don’t know what they mean by that,” he says, arguing that the NIST definition could have the effect of excluding truly critical elements such as firewalls “simply because they’re on devices rather than cloud-based.”

Greenwald realizes that NIST might prefer not to initially include software that’s embedded on a chipset in a device. “But when you’re talking about an operating system, or application layer software, it doesn’t make sense to me that you would exclude that as a category. It’s hard to understand how they could be drawing a meaningful distinction between device software as opposed to firmware.”

“Complexity” is no justification for the distinction, he says. “I would argue that the more complex it is, the more important to have elevated security standards applied to it.”

A possible motivation for NIST to draw the line at embedded software and firmware is a desire “not to bite off more than they can chew” in the initial implementation phase of the executive order, Greenwald acknowledges. By overreaching in its definition of what constitutes critical software, the agency would risk dissuading private tech companies from participating in federal government procurement. Still, he says, that’s not a legitimate reason to exclude that class of software from early action.

The distinction might seem academic to some, but it goes to the heart of which technology providers can be trusted to supply key security systems to both government and the private sector. The Department of Defense recently tightened its own standards for procurement, with issuance of its Cybersecurity Maturity Model Certification. CMMC dictates that eligible contractors obtain third-party certifications in order to sell their software to DOD.

Greenwald sees the possibility of instituting a regime that instantly sweeps up hundreds of thousands of contractors in a rigorous compliance initiative. “There are questions about who exactly is supposed to be subject to these,” he says. “Lack of clarity is the devil.”

But lack of clarity is also Greenwald’s concern when it comes to NIST’s apparent dismissal of embedded software and firm as critical elements requiring immediate attention by Biden’s newly appointed task force on supply chain disruptions. He has hopes that the agency will soon clarify its intent, or that CISA will choose to include the disputed category in its definitive list of applicable software.

Still, if both agencies continue to pass over those components for phase one of the executive order, “I feel quite confident that they will be included in phase two,” Greenwald says. Omitting them altogether would seriously jeopardize efforts to secure systems against any manner of cyber threat.

Technology Regulation & Compliance Supply Chain Security & Risk Mgmt Aerospace & Defense High-Tech/Electronics

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • 021_what_is_ai_in_warehousing_and_the_supply_chain- (540p).png

    Watch: What Is AI in Warehousing and the Supply Chain?

    Artificial Intelligence
  • TWO WORKERS IN A WAREHOUSE PUSH ROLLING CARTS LOADED WITH BRIGHT BLUE BINS

    Walmart Caps Usage of an AI Tool for Employees After High Demand

    Artificial Intelligence
  • Close-up hands of unrecognizable man holding and using smartphone standing on city street.

    Five Supply Chain Security Risks Hiding Inside Your Mobile Apps

    Supply Chain Visibility
  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing