DER Digital Supply Chain Gap Analysis
Example Recommendations
Funded by:
SOLAR ENERGY
TECHNOLOGIES OFFICE
U.S. Department of Energy
Recommendation 30: Through a secure portal, vendors should provide customers with a
vulnerability disclosure report, including the analysis and findings describing the impact that
a reported vulnerability has on a product as well as plans to address the vulnerabilities. The
vulnerability disclosure report should be signed with a trusted, verifiable, private key that
includes a time stamp of the signature. (Adapted from NIST SP 800-161r1 RA-5; NATF Energy
Sector Supply Chain Risk Questionnaire RISK-08)
Recommendation 31: Vendors should establish a separate notification channel for customers
in case a vulnerability arises that is not included in the vulnerability disclosure report.
(Adapted from NIST SP 800-161r1 RA-5; NATF Energy Sector Supply Chain Risk Questionnaire
VULN-06, VULN-07)View entire presentation