{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T21:28:37Z","timestamp":1778275717254,"version":"3.51.4"},"reference-count":115,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Korean Research Institute for Defense Technology Planning and Advancement grant funded by Korean Government","award":["KRIT-CT-22-088"],"award-info":[{"award-number":["KRIT-CT-22-088"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/access.2025.3573515","type":"journal-article","created":{"date-parts":[[2025,5,26]],"date-time":"2025-05-26T18:04:18Z","timestamp":1748282658000},"page":"96813-96833","source":"Crossref","is-referenced-by-count":1,"title":["Comprehensive Analysis and Recommendation of Supply Chain Risk Management Framework for the Military Domain"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-4897-7453","authenticated-orcid":false,"given":"Jung Keun","family":"Ahn","sequence":"first","affiliation":[{"name":"School of Cybersecurity, Korea University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9863-5075","authenticated-orcid":false,"given":"Kwangsoo","family":"Cho","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Korea University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kyungdeok","family":"Seo","sequence":"additional","affiliation":[{"name":"Hanwha Systems Company Ltd., Seongnam, Gyeonggi, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyun-Ji","family":"Kim","sequence":"additional","affiliation":[{"name":"Hanwha Systems Company Ltd., Seongnam, Gyeonggi, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2157-0403","authenticated-orcid":false,"given":"Seungjoo","family":"Kim","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Korea University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"3","article-title":"Environmental change, human civilization and sustainable development","volume":"46","author":"Jung","year":"2008","journal-title":"J. Environ. Stud."},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-37r2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-53r5"},{"key":"ref4","volume-title":"ICT Investment | OECD","year":"2024"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1057\/s41284-024-00435-3"},{"issue":"3","key":"ref6","first-page":"304","article-title":"A theoretic study on the critical success factors for implementation of ict supply chain","volume":"2016","author":"Jin","year":"2016","journal-title":"Korea IT service Acad."},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1080\/13675560310001627016"},{"key":"ref8","volume-title":"Security and Resilience\u2013Security Management System\u2013Requirements","year":"2023"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-161r1"},{"key":"ref10","volume-title":"SW Supply Chain Security Guideline V1.0","year":"2024"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCNT51525.2021.9579611"},{"key":"ref12","article-title":"The race to the vulnerable: Measuring the Log4j shell incident","author":"Hiesgen","year":"2022","journal-title":"arXiv:2205.02544"},{"key":"ref13","volume-title":"Supply Chain Attack Against 3CXDesktopApp | CISA","year":"2024"},{"key":"ref14","volume-title":"CVE-2024-3094","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106267"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.5771\/9780810886421"},{"key":"ref17","volume-title":"Fact Sheet: National Strategy for Global Supply Chain Security","year":"2024"},{"key":"ref18","volume-title":"Executive Order 14017-America\u2019s Supply Chains","year":"2024"},{"key":"ref19","volume-title":"The Council Agrees to Strengthen the Security of ICT Supply Chains","year":"2024"},{"issue":"1","key":"ref20","first-page":"1","article-title":"The regulation of supply chain cybersecurity in the nis2 directive in the context of the Internet of Things","volume":"15","author":"van\u2019t Schip","year":"2024","journal-title":"Eur. J. Law Technol."},{"key":"ref21","volume-title":"Supply chain risk management fundamental theory and guideline to build a resilient supply chain","author":"Villegas","year":"2020"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/s10479-023-05431-1"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1111\/opec.12287"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.3390\/horticulturae8111018"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.jenvman.2023.119809"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.ecolind.2023.110992"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1504\/IJLSM.2020.103862"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s10668-023-03195-z"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.gexplo.2023.107352"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TEM.2017.2652382"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3544421"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564556"},{"key":"ref33","volume-title":"Common Vulnerability Scoring System","year":"2025"},{"key":"ref34","volume-title":"Threat Modeling: Designing for Security","author":"Shostack","year":"2014"},{"key":"ref35","volume-title":"Threat Modeling: A Practical Guide for Development Teams","author":"Tarandach","year":"2020"},{"key":"ref36","article-title":"SoK: A systems perspective on compound AI threats and countermeasures","author":"Banerjee","year":"2024","journal-title":"arXiv:2411.13459"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.14722\/aiscc.2024.23016"},{"key":"ref38","volume-title":"Using Nist Sp 800-161 for Cybersecurity Supply Chain Risk Management","author":"Staff","year":"2025"},{"key":"ref39","volume-title":"MITRE ATT&CK: A Knowledge Base of Adversary Tactics and Techniques","year":"2025"},{"key":"ref40","volume-title":"CWE\u2013Common Weakness Enumeration","year":"2025"},{"key":"ref41","volume-title":"CVE-Common Vulnerabilities and Exposures","year":"2025"},{"key":"ref42","volume-title":"Ai\u2019s Role in the Future of Your Supply Chain: Benefits and Risks","author":"Mariani","year":"2025"},{"key":"ref43","volume-title":"5 Models of AI for Supply Chain Risk Management-and Why They Matter","author":"Team","year":"2025"},{"key":"ref44","volume-title":"Recommendations for Software Bill of Materials (SBOM) Management","year":"2024"},{"key":"ref45","volume-title":"Guidance on Introduction of Software Bill of Materials (SBOM) for Software Management","year":"2024"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-218"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-204d"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1177\/15485129241267919"},{"key":"ref49","volume-title":"Blockchain Technologies in Supply Chain Management","year":"2025"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3315571"},{"key":"ref51","article-title":"No more chewy centers: Introducing the zero trust model of information security","author":"Kendervarg","year":"2010"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-207"},{"key":"ref53","volume-title":"Executive Order 14028-Executive Order on Improving the Nation\u2019s Cybersecurity","year":"2024"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.3390\/su141811213"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3425350"},{"key":"ref56","doi-asserted-by":"crossref","DOI":"10.2139\/ssrn.4530357","article-title":"Digital twin model of semiconductor supply chain for managing disruption and resilience through data driven experiments","author":"Kek","year":"2023"},{"key":"ref57","year":"2025","journal-title":"New IEEE Global Survey: Technologists Expect AI to be the Most Important Technology of 2025"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3660853.3660932"},{"key":"ref59","volume-title":"DLA Applying AI to Supply Chain Risk Management, Warfighter Readiness","author":"Reece","year":"2025"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-61r3"},{"key":"ref61","volume-title":"U.S. Code, Title 41, Section 1321-1328"},{"key":"ref62","volume-title":"Cyber Supply Chain Risk Management","author":"Centre","year":"2024"},{"key":"ref63","volume-title":"Identifying Cyber Supply Chain Risks","author":"Centre","year":"2024"},{"key":"ref64","article-title":"Good practices for supply chain cybersecurity","author":"Papaphilippou","year":"2023"},{"key":"ref65","volume-title":"Risk Management\u2013Guidelines","year":"2018"},{"key":"ref66","volume-title":"Security Management Systems for the Supply Chain\u2013Best Practices for Implementing Supply Chain Security, Assessments and Plans\u2013Requirements and Guidance","year":"2012"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/SAMI60510.2024.10432797"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/ISDFS58141.2023.10131834"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.2989644"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2016.260"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/ICIDCA56705.2023.10099966"},{"key":"ref72","article-title":"Enisa threat landscape for supply chain attacks","author":"Lella","year":"2021"},{"key":"ref73","volume-title":"DoDIN Approved Products List","year":"2024"},{"key":"ref74","volume-title":"Military Aviation Authority","year":"2024"},{"key":"ref75","volume-title":"NATO Information Assuarance Product Catalogue","year":"2024"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-12206-9_28"},{"key":"ref77","volume-title":"DoD Program Manager\u2019s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) Into the System Acquisition Lifecycle","year":"2015"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.32604\/iasc.2021.015845"},{"key":"ref79","first-page":"22","article-title":"Huawei versus the United States? The geopolitics of exterritorial Internet infrastructure","volume":"14","author":"Tang","year":"2020","journal-title":"Int. J. Commun."},{"key":"ref80","first-page":"827","article-title":"A study on constructing a RMF optimized for Korean national defense for weapon system development","volume":"33","author":"Ahn","year":"2023","journal-title":"J. The Korea Inst. Inf. Secur. Cryptol."},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/SYNASC.2017.00035"},{"key":"ref82","volume-title":"Writing Secure Code","author":"LeBlanc","year":"2002"},{"key":"ref83","article-title":"Threat assessment and remediation analysis (TARA)","author":"Wynn","year":"2014"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.21236\/ADA470450"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1002\/9781118988374"},{"key":"ref86","volume-title":"Trike V. 1 Methodology Document [Draft]","author":"Saitta","year":"2005"},{"key":"ref87","volume-title":"Code","year":"2024"},{"key":"ref88","volume-title":"GitHub-USArmyResearchLab\/Dshell","year":"2024"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-83r1"},{"key":"ref90","volume-title":"Common Vulnerability Scoring System V3.1: Specification Document","year":"2024"},{"key":"ref91","volume-title":"Thwarted Supply-chain Hack Sets Off Alarm Bells Across DC","author":"Sakellariadis","year":"2024"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.14254\/1800-5845\/2018.14-2.10"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1108\/02756660310494854"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38928-3_5"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106246"},{"key":"ref96","article-title":"An empirical study on package-level deprecation in Python ecosystem","author":"Zhong","year":"2024","journal-title":"arXiv:2408.10327"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00093"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3443741"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/MSR59073.2023.00015"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3117771"},{"key":"ref101","volume-title":"NPM Security Update: Attack Campaign Using Stolen Oauth Tokens","author":"Ose","year":"2024"},{"key":"ref102","volume-title":"You\u2019re Spreading Malwares on Your Requirements","year":"2024"},{"key":"ref103","volume-title":"CVE-2023\u20137028","year":"2024"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1145\/3145905"},{"key":"ref105","first-page":"482","article-title":"Comparative analysis of information security governance frameworks: A public sector approach","volume-title":"Proc. 11th Eur. Conf. eGovernment-ECEG","author":"Rebollo"},{"key":"ref106","volume-title":"Risk Management Framework for DoD Systems","year":"2022"},{"key":"ref107","volume-title":"Definition of Critical Software Under Executive Order (EO) 14028","year":"2025"},{"key":"ref108","volume-title":"Software Supply Chain Security Guidance Under Executive Order (EO) 14028 Section","year":"2024"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.6028\/nist.ir.8397"},{"key":"ref110","volume-title":"The Minimum Elements for a Software Bill of Materials (SBOM)","year":"2024"},{"key":"ref111","volume-title":"An analysis of SBOM in the context of software supply-chain risk management","author":"Haque","year":"2023"},{"key":"ref112","volume-title":"Common Security Contorls for Hardware Supply Chain Security Verification","year":"2024"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1109\/ICACITE57410.2023.10182662"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/PST58708.2023.10320170"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1080\/24725838.2024.2321460"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/10820123\/11015467.pdf?arnumber=11015467","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,7]],"date-time":"2025-06-07T04:26:32Z","timestamp":1749270392000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11015467\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":115,"URL":"https:\/\/doi.org\/10.1109\/access.2025.3573515","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}