<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Adrian Davis</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Building Cyber-Resilience into Supply Chains</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cyber-resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">direct suppliers</style></keyword><keyword><style  face="normal" font="default" size="100%">indirect suppliers</style></keyword><keyword><style  face="normal" font="default" size="100%">information-centric approach</style></keyword><keyword><style  face="normal" font="default" size="100%">procurement</style></keyword><keyword><style  face="normal" font="default" size="100%">requirements</style></keyword><keyword><style  face="normal" font="default" size="100%">resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">supply chain</style></keyword><keyword><style  face="normal" font="default" size="100%">Tier 1 suppliers</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">04/2015</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/887</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">5</style></volume><pages><style face="normal" font="default" size="100%">19-27</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The article discusses how an organization can adopt an information-centric approach to protect its information shared in one or more supply chains; clearly communicate the expectations it has for a direct (Tier 1) supplier to protect information; and use contracts and measurement to maintain the protection desired. Building on this foundation, the concept of resilience – and that of cyber-resilience – is discussed, and how an information-centric approach can assist in creating a more cyber-resilient supply chain. Finally, the article concludes with five steps an organization can take to improve the protection of its information:  i) map the supply chain; ii) build capability; iii) share information and expertise; iv) state requirements across the supply chain using standards, common frameworks, and languages; and v) measure, assess, and audit.</style></abstract><issue><style face="normal" font="default" size="100%">4</style></issue><custom1><style face="normal" font="default" size="100%">(ISC)&lt;sup&gt;2&lt;/sup&gt;
Adrian Davis, PhD, MBA, FBCS CITP, CISSP, heads the Europe, Middle East, and Africa (EMEA) team for (ISC)&lt;sup&gt;2&lt;/sup&gt;, the global, not-for-profit leader in educating and certifying information security professionals throughout their careers. His role is to deliver the (ISC)&lt;sup&gt;2&lt;/sup&gt; vision of inspiring a safe and secure cyber-world and its mission of supporting and providing members and constituents with credentials, resources, and leadership to secure information and deliver value to society. Before working for (ISC)&lt;sup&gt;2&lt;/sup&gt;, Adrian delivered practical business solutions to over 360 blue-chip multinational clients for the Information Security Forum. His expertise included: managing information security in supply chains; information security governance and effectiveness; the relationship between information security and business continuity; and possible near-term threats to organizations. Adrian regularly attends and chairs conferences and contributes articles for the press. He also contributed to the development of &lt;em&gt;ISO/IEC 27014: Governance of Information Security&lt;/em&gt; and currently acts as a co-editor for &lt;em&gt;ISO/IEC 27036 Information Security in Supplier Relationships, Part 4: Guidelines for Security of Cloud Services&lt;/em&gt;.</style></custom1></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Ute Reuter</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Implementation Prerequisites for Electronic Procurement of Services</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">digitalization</style></keyword><keyword><style  face="normal" font="default" size="100%">electronic procurement</style></keyword><keyword><style  face="normal" font="default" size="100%">implementation</style></keyword><keyword><style  face="normal" font="default" size="100%">improvement</style></keyword><keyword><style  face="normal" font="default" size="100%">process innovation</style></keyword><keyword><style  face="normal" font="default" size="100%">procurement</style></keyword><keyword><style  face="normal" font="default" size="100%">purchasing</style></keyword><keyword><style  face="normal" font="default" size="100%">service management</style></keyword><keyword><style  face="normal" font="default" size="100%">service procurement</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">02/2015</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/870</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">5</style></volume><pages><style face="normal" font="default" size="100%">15-23</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Service procurement is a business function of increasing importance and is highly suitable for integration of electronic support, but it suffers from severe research deficits. As yet, implementation prerequisites for electronic procurement of services are obscure and not quantifiable. In this research project, organization, formalization, and specialization of procurement and standardization and strategic importance of the procured services are identified as relevant implementation prerequisites. Measurement models for these prerequisites are established and proven through quantitative empirical research. As such, this article is a major step towards a more rigorous investigation of electronic procurement of services.</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><custom1><style face="normal" font="default" size="100%">VWA-University of Extra-Occupational Studies
Ute Reuter is Professor of Business Economics, specializing in company management, human resource management, and organization, at VWA-University of Extra-Occupational Studies in Stuttgart, Germany. She holds a doctoral degree from Stuttgart University, Germany, and two diploma degrees: one in Business Economics from Hohenheim University, Germany, and one in Administrative Studies from the Federal University of Business Administration in Bonn, Germany. She researches in the areas of innovation, procurement, service management, digitalization, and company management and is especially interested in topics interlinking these different research areas.</style></custom1></record></records></xml>