Your Zero Trust Stops at the Sticker on the Box
Zero trust verifies every user, device and request. Then it runs on a switch you trust because a label says who made it. Roei Ganzarski of Alitheon on hardware provenance, the fake-paperwork aircraft parts that flew for years, and the six-step intake pipeline a startup can run this quarter.
Eleven minutes into episode 103, Roei Ganzarski said the thing I haven’t stopped thinking about since we recorded it. I had put my security hat on and asked about hardware tampering in transit. He answered with a question about the framework every security leader in the audience has already bought into.
Zero trust says verify everything that connects to your network. Fine. The cyber runs on hardware. And you trust the hardware because a sticker says who made it and where.
“Your entire cybersecurity zero trust could be running on hardware that gives a backdoor or listens in or manipulates any of your data, and you’ll have no clue until it’s too late.”
Roei Ganzarski, President and Chief Executive Officer of Alitheon, on episode 103
Roei runs Alitheon, the Bellevue, Washington company behind FeaturePrint, and he has made that argument to rooms full of cybersecurity people who told him hardware isn’t their problem. This post is my attempt to take the argument seriously: what the zero trust frameworks actually say about hardware, what the best-documented paperwork fraud in recent aviation history proves about labels, and what a 30-person company can do about it before the next security questionnaire asks.
What zero trust actually says about hardware
The awkward part is that the frameworks already agree with Roei. The National Institute of Standards and Technology’s Special Publication 800-207, the document most zero trust programs cite as their foundation, lists seven tenets, and the fifth reads: “The enterprise monitors and measures the integrity and security posture of all owned and associated assets.” The explanatory text adds that “no asset is inherently trusted” (NIST SP 800-207, Zero Trust Architecture). The Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model goes further: its Devices pillar has four functions, and one of them is named “Asset & Supply Chain Risk Management.” Its description of the lowest maturity stage will sound familiar to most startups: assets not tracked “in an enterprise-wide or cross-vendor manner,” supply chain acquisition managed “in ad hoc fashion with a limited view of enterprise risks” (CISA Zero Trust Maturity Model, version 2.0, PDF).
So the gap isn’t in the doctrine. It’s in what teams implement when they say “device trust,” which is almost always a management agent phoning home from a machine whose identity nobody verified on arrival. The agent attests to disk encryption, patch level and a compliant configuration. It cannot attest that the chassis it’s running inside is the chassis the manufacturer built, because it learned everything it knows from that chassis.
Gartner put a number on the shape of the problem when it predicted that “through 2026, more than half of cyberattacks will be aimed at areas that zero-trust controls don’t cover and cannot mitigate” (Gartner, January 2023). And HP Wolf Security’s 2024 survey of 803 IT and security decision makers found that 45 percent “have to trust suppliers are telling the truth as they don’t have the means to validate hardware and firmware security claims,” while 52 percent said procurement rarely works with security to verify those claims at all (HP Wolf Security, Securing the Device Lifecycle, December 2024). That is the sticker, quantified: nearly half of the people responsible for device security take the label’s word for it because they have nothing else to go on.
Roei’s argument is that they could have something else. The upside of hearing it from someone outside our industry is that he doesn’t start from the network at all. He starts from how governments learned to identify people.
Biometrics for things: how FeaturePrint reads the part instead of the paperwork
We used to identify a human with a badge or a passport. Then governments worked out that a proxy can be lost, transferred, faked or manipulated, so they moved to fingerprints and irises, which are unique, inherent and always with you. Roei’s example is a twin who walks into a building on his brother’s real driver’s license: the document is real, the person is real, and the link between them is the lie. Physical products, he argues, are still stuck at the proxy stage. A barcode. A hologram that reads as authentic mostly because it’s shiny and the picture changes when you tilt it. A sticker.
“At best, you know that the proxy is what it says it is. At worst, even the proxy is fake.”
Roei Ganzarski, Alitheon, episode 103
The mechanism behind FeaturePrint is the part of the episode worth hearing him explain in his own words, because it turns a manufacturing nuisance into a security property. No machine can make the same thing twice. Every design engineer knows this, which is why they publish a tolerance band, and everything inside that band passes quality control, looks identical and works identically. Alitheon’s math reads the differences that are still there inside the band and turns them into what the company calls a FeaturePrint. The fingerprint exists only because the object was manufactured, so it can’t be peeled off, swapped, or re-issued with the paperwork. Roei puts the odds of two products carrying the same manufacturing signature at one in six and a half trillion, and he is specific that there is no training phase and, in his words, no machine learning anywhere in it. Alitheon’s own site markets the product as optical AI built on machine vision, with no training data needed and a fingerprint file of 500 kilobytes or less (Alitheon); the two descriptions are of the same system from two angles. It runs on off-the-shelf industrial cameras, and for some items a phone.
I asked the obvious security question: how does tampered hardware get from a warehouse into a data center without anyone noticing? Roei’s answer was that the usual checks are impedance tests and destructive sampling, you pull a unit and take it apart, and that the software above the hardware never checks the hardware at all. His alternative is disarmingly simple.
“How about just taking a picture of it and saying that’s not what that company made in their factory.”
Roei Ganzarski, Alitheon, episode 103
There is a landscape here worth naming plainly. Some approaches add something to the object: DUST Identity’s diamond-dust tags, which Rod Schultz walked us through back on episode 29, molecular markers, security inks. Physically unclonable functions do a version of this for chips, deriving a secret from silicon manufacturing variation. Alitheon’s bet is to add nothing and read what the machine already left. In June 2026 the company raised an $8 million Series A1 led by Emerald Technology Ventures with eBay Ventures, bringing its total to a little over $40 million, and it holds more than 55 issued patents (GeekWire, June 2026). GeekWire also had Roei demonstrate the system on camera, which is the fastest way to see a photograph tell two identical parts apart.
Real parts, fake paperwork: what the AOG Technics case proves about labels
The story from the episode that I keep retelling has nothing to do with chips. Roei describes an aircraft engine supplier in the United Kingdom caught selling real used parts with paperwork saying they were new, parts that in his telling had reached the end of their life and should have been destroyed, flying in commercial aircraft for about five years before anyone noticed, and it wasn’t an accident that found it. His conclusion is the line the whole episode turns on: the industry relies on paperwork because paperwork is easy.
He doesn’t name the company on tape, and the public case that matches his description is AOG Technics, so I went and read the record. It is narrower than the retelling in one way and more alarming in another. What the courts proved is document forgery at scale. On February 23, 2026, the United Kingdom’s Serious Fraud Office announced that director Jose Zamora Yrala had been sentenced to four years and eight months after pleading guilty to fraudulent trading; between January 2019 and July 2023 his company sold more than 60,000 parts accompanied by forged Authorised Release Certificates, the documents that certify a part’s origin and condition, causing an estimated £39.3 million in losses to airlines and manufacturers (UK Serious Fraud Office, February 2026). CFM International, the GE Aerospace and Safran joint venture that builds the CFM56 engine on most Boeing 737s and Airbus A320s, counted 126 affected engines by October 2023 (AeroTime, October 2023). American, Southwest, United, Delta and Virgin Australia all found affected parts, and aircraft came out of service while they were replaced.
Three details matter for anyone who runs infrastructure. First, how it was caught: engineers at TAP Air Portugal’s maintenance arm were servicing a CFM56 when a replacement part whose paperwork claimed new production showed visible wear, so they asked Safran to verify it, and Safran confirmed the certificate was forged (Insurance Journal, via Bloomberg, December 2025). A human held the object next to its proxy and noticed they disagreed. Second, the paperwork itself was the product: the forged documents were FAA Form 8130-3 and EASA Form 1 release certificates, and the Federal Aviation Administration’s notification on one of them lists the tells, a wrong block description, a missing responsibilities section, formatting GE never used (FAA Unapproved Parts Notification 2023-AAE-EHL-20230801-713). Third, and this is where the record is narrower than the retelling, the FAA concluded that no critical parts had been found with forged certificates and that the concern did not warrant an airworthiness directive (AeroTime, December 2023). The company never disclosed where the parts came from, so their history is unknown rather than proven bad. Bolts, nuts, seals and bushings of undisclosed origin flew for years under perfect paperwork, and the paper was the only thing anyone could verify.
The industry’s own diagnosis is the same as Roei’s. The Aviation Supply Chain Integrity Coalition, formed by Airbus, Boeing, GE Aerospace, Safran, StandardAero, American, Delta and United after the scandal, wrote that the sector relies on “physical paperwork, which can be both easier to counterfeit and more difficult to process in a timely manner” (Aviation Supply Chain Integrity Coalition). Christian Klein of the Aeronautical Repair Station Association put it more bluntly: “Overreliance on paperwork paired with a lack of clear consequences have left a gap crooks can exploit” (ARSA, October 2023).
There’s a grim coincidence in the calendar. On September 8, 1989, exactly 37 years before this post went up, Partnair Flight 394 broke apart over the sea off Denmark and killed all 55 people on board; three of the four bolts holding the tail on were counterfeit, heat-treated wrong and able to bear only about 60 percent of their intended load (Partnair Flight 394). That was the accident that taught aviation to fear bogus parts. AOG Technics is the reminder that the fix aviation built, a lifetime of paperwork that travels with every part, is itself a proxy, and proxies can be printed.
Counterfeit, gray market, and tampered: three hardware problems that share a label
Roei is careful to separate two problems that get lumped together, and I’d add a third. A counterfeit is a fake object. A gray market product is a real object moving through a channel the manufacturer never authorized, and Roei notes that a customer’s own distributors are sometimes the people being caught. Tampered hardware is a real object that was altered on the way to you. From the outside, all three carry exactly the same sticker.
The counterfeit case every network engineer should know is Onur Aksoy’s. Through at least 19 companies and dozens of Amazon and eBay storefronts, he imported fake Cisco networking gear from China and Hong Kong and sold it as genuine, generating more than $100 million in revenue over roughly a decade. In May 2024 he was sentenced to 78 months in prison and ordered to pay $100 million in restitution to Cisco. The Department of Justice’s account of where the equipment ended up is the part to read twice: the devices “ended up in U.S. hospitals, schools, and highly sensitive military and other governmental systems,” including platforms supporting fighter jets and maritime patrol aircraft (U.S. Department of Justice, May 2024). Every one of those boxes passed receiving. Every one had a sticker.
What counterfeits do to your security posture is documented too. In 2020, F-Secure analyzed two counterfeit Cisco Catalyst 2960-X switches that an IT company had been running until a software update made them fail, and found the fakes contained a flaw that let the device’s Secure Boot protections be bypassed. F-Secure found no backdoor, and later noted the same vulnerability affected genuine units as well, but its conclusion stands: the security posture of the device was weakened in a way nobody who bought it could see (SecurityWeek, July 2020). Cisco’s later field notice for that switch family is exactly the kind of “ask the object” check Roei is describing: it added a signed Secure Unique Device Identifier check, so an administrator can challenge the silicon with a nonce and compare the certificate’s serial and product ID against what the sticker claims (Cisco Field Notice FN-72399).
Gray market is the quieter problem, and it’s the delivery vector for the other two. Cisco’s brand protection page lists what arrives through unauthorized channels: diverted, stolen, end-of-support, or “compromised” gear that “may have been altered to be less secure” (Cisco Brand Protection), and the U.S. State Department’s inspector general issued a fraud alert in 2025 on grey market Cisco devices, recommending authorized resellers only, serial verification through the vendor portal, and regular equipment audits (Department of State Office of Inspector General, April 2025). None of this is new. A 2012 Senate Armed Services Committee inquiry found 1,800 cases of suspect counterfeit electronic parts in the defense supply chain, involving more than a million parts (Senate Armed Services Committee, May 2012), and the latest OECD and EUIPO estimate puts global trade in counterfeit goods at roughly 467 billion dollars in 2021, about 2.3 percent of global imports (EUIPO, June 2025; full report: OECD, Mapping Global Trade in Fakes 2025).
Tampering is the one Roei asked me about, and it is the reason factory seals should reassure nobody. Documents published in 2013 and 2014 described a routine intelligence practice called interdiction: network hardware intercepted in transit, implanted, and repackaged complete with factory seals before delivery (TechCrunch, May 2014). Whatever you think of the actor, the technique is the point. Shrink-wrap is a sticker too.
“One of the things I’m learning on this job, which is scary, is human greed has no boundaries. There are no red lines.”
Roei Ganzarski, Alitheon, episode 103
High consequence items: the syringe that knows its own manufacturing date
Roei sells into four markets that he says are all versions of one idea: high consequence items. Expensive goods like the gold bullion that goes into national banks. Anything that goes in or on a body. Transportation parts and defense articles, where the consequence of getting it wrong is somebody getting hurt. The fake Rolex, in his framing, is the easy version of the problem.
The example that made the mechanism click for me was a syringe. The box carries the serial and the expiration date, and the box is what gets inspected. FeaturePrint the syringe itself at the point of manufacture and the object knows its own production date; a box that says 2028 wrapped around a syringe made in 2026 becomes a detectable contradiction instead of an invisible one. It closes a loophole that no amount of box printing can.
“Who buys a product for the box? You buy it for the product.”
Roei Ganzarski, Alitheon, episode 103
Pharma is instructive because it is the one industry that legislated unit-level identity, and the timeline shows how hard that is. The Drug Supply Chain Security Act’s requirement for interoperable, electronic, package-level tracing legally took effect on November 27, 2023, but the Food and Drug Administration granted a stabilization period through November 2024 and then staggered exemptions that run as late as November 2027 for the smallest dispensers (FDA, Implementing DSCSA; FDA, DSCSA exemptions). A decade of statute to serialize the box. The World Health Organization’s estimate of why it matters is the one that sticks: roughly 1 in 10 medical products circulating in low- and middle-income countries is substandard or falsified (WHO, November 2017).
Gold makes the same point with fewer words. In 2020, more than a dozen Chinese lenders discovered that 83 tons of gold bars pledged as collateral for about $2.8 billion in loans were gilded copper; the bars had been vaulted, insured and audited, and nobody had drilled one (Caixin Global, June 2020). Two years later the London Bullion Market Association and the World Gold Council launched a Gold Bar Integrity programme to build “an international system of gold bar integrity, chain of custody and provenance” (LBMA, March 2022), and in February 2023 the LBMA selected Alitheon to bring authentication and traceability to the gold market, with the refiner Argor-Heraeus among the early adopters (PR Newswire, February 2023). Roei mentions on the show that several customers won’t publicize that they use FeaturePrint at all, which tells you something about how the buyers of high consequence items think about the people selling into them.
One more detail for whoever approves vendors: Alitheon doesn’t need to keep the images, or much data at all. The FeaturePrint is a compact file that can run in the cloud or on premises, and as I said to Roei on the tape, it basically is a digital signature for an object. A provenance system that holds a fingerprint rather than a photo library is a much easier security review.
Hardware provenance for startups: the intake pipeline you can run this quarter
Here is where I bring this home, because almost nobody reading this is going to photograph a jet engine. The version of Roei’s argument that we run into at YSecurity is smaller and arrives sooner: the asset question in a buyer’s security review.
A founder gets a vendor security questionnaire with a line about hardware and asset provenance on it, and the honest answer is that a contractor bought three laptops on a corporate card and shipped them to new hires directly. Nobody logged the serials. There’s no receiving step to describe, because there’s no receiving. That answer doesn’t fail the deal by itself. What it does is turn one questionnaire line into a follow-up call, and the follow-up call is where a diligence process starts pulling on everything adjacent to it. The good news is that the boring answer is cheap to build, and it maps onto every framework the buyer is likely to name.
Procure through channels you can name. Buy from authorized resellers only, and register them. Apple Business Manager lets you add your Apple customer number and each reseller’s number so devices you buy through them appear in your organization by serial, submitted by Apple or the reseller rather than typed in by you (Apple Business Manager, manage device suppliers). That is a purchase-chain guarantee, and it is the closest thing to provenance most startups get for free.
Receive on purpose. Log the serial, photograph the label and seals, and do it before the person who will use the machine opens the box. This is the TAP Air Portugal mechanic’s move, institutionalized: put the object next to its paperwork once, with a record. The SOC 2 criteria expect exactly this; the point of focus under CC6.1 is that the entity “identifies, inventories, classifies, and manages information assets,” and CC9.2 asks you to assess and manage vendor risk (AICPA Trust Services Criteria). If you’ve read our plain-English guide to SOC 2, this is the control behind the questionnaire line.
Enroll before first login. Automated Device Enrollment on Apple hardware and Windows Autopilot on the rest mean the device is supervised and managed before anyone types a password into it (Apple, Automated Device Enrollment; Microsoft, registering Autopilot devices). Microsoft’s guidance is telling: device owners can only self-register by hardware hash, and the stronger path is to have the manufacturer or reseller register the device at the factory. Provenance, again, is a property of the channel.
Attest with the silicon, not the sticker. This is the step Roei would recognize. Apple’s Managed Device Attestation uses the Secure Enclave to give your management server “cryptographic assurances about the identity of a device and its security posture,” including its serial number and boot configuration, signed by a key only that specific chip could have generated (Apple Platform Security, Managed Device Attestation). On Windows, the Trusted Platform Module’s measured boot and key attestation do the same job (Trusted Computing Group, What is a TPM), and on Cisco gear the SUDI check above takes one command. Jasson Casey made the people version of this argument on episode 92, which became our case for device-bound credentials: bind the secret to the hardware and the phish stops working. Attestation points the same idea at the hardware itself. One caution: attestation proves the firmware and silicon are what the vendor signed, and the purchase chain proves where the box came from. Neither proves the other. You want both.
Reconcile monthly. Inventory against identity provider against management console. Every device in one list and not the others is a finding, and it’s the finding the buyer’s security team will look for first. This is CIS Control 1 in one sentence, “actively manage (inventory, track, and correct) all enterprise assets” (CIS Controls, Control 1), and ISO/IEC 27001:2022 asks for the same inventory in A.5.9 and for supply chain security in A.5.21 (ISO/IEC 27001:2022). If you sell into defense, NIST Special Publication 800-53’s SR-11, Component Authenticity, expects an anti-counterfeit policy with “the means to detect and prevent counterfeit components from entering the system” (NIST SP 800-53 Rev. 5, SR-11), which is where our CMMC Level 2 work and this post overlap; NIST SP 800-161 is the deeper reference (NIST SP 800-161 Rev. 1, Update 1). CISA’s Hardware Bill of Materials Framework gives vendors and buyers a shared format for saying what’s inside the box (CISA, HBOM Framework), and the caveat we made about training data in the AI data bill of materials applies here too: a bill of materials tells you what should be there. Something else has to confirm that it is.
Retire the same way. Offboarding is intake in reverse: wipe, revoke, record. The forgotten devices we wrote about in IoT device security and the printer that takes down 11,000 devices are what happens when the loop never closes.
If that list reads as a lot, notice that steps one through three and five through six are process, and cost nothing but discipline. Step four is the only one that asks the object a question, and it is the one Roei built a company around. Chris Kirschke made the software version of the same point two episodes ago in are you actually going to give the agent write access: if you can’t trust the inputs, you’ll never trust the output. Hardware is the input under all the other inputs.
The mercenary CEO and the Friday question
The episode is 46 minutes and the second half is a leadership conversation I didn’t expect. Roei isn’t a founder of Alitheon. He calls himself a mercenary CEO: this is the fourth time, by his count, that a group of mathematicians and physicists built something remarkable and then brought him in to turn it into a business. His degrees are in economics and business, and he says the pleasure of the job is usually being the least smart person in the room. His rule for the team is that they don’t have to explain the math to their mother; they have to explain it to him, and if he gets it, the company can tell the story. Before Alitheon he ran magniX, where the team flew an all-electric commercial aircraft, a converted Harbour Air seaplane, in December 2019 (Harbour Air and magniX, December 2019), which he says came twelve months after the team started, on a timeline the industry had called impossible.
He also runs a Friday all-hands at every company he has joined that starts with Arabic coffee he makes himself and one question: who made a really cool mistake this week? It is the most useful engineering-management idea I’ve heard on the show this year, and it comes from a man whose product exists because manufacturing can’t help making tiny mistakes.
“AI can help you tremendously. But don’t let it think for you.”
Roei Ganzarski, Alitheon, episode 103
His ask for the audience is bigger than the usual “check out our developer portal.” He wants critical thinking back, and he is specific about the threat to it: handing the questioning to a large language model because it’s easier than doing it yourself. Coming from someone whose entire business is refusing to take a label’s word for it, that lands.
The rule worth stealing: a label is an assertion, never evidence
For a scaling startup, the whole episode compresses into one line I now use in questionnaire reviews: a sticker is an assertion about the object, never evidence of it. The serial on the laptop, the release certificate on the part, the assay stamp on the bar, the factory seal on the box: each one tells you what somebody claims. Zero trust earned its name by refusing to accept that kind of claim from a user or a network. Extending the same refusal to the hardware is the doctrine’s own fifth tenet, and the practical version fits in six steps.
If your next security review has a hardware or asset line on it and you’d like the answer to be boring, our sales support team writes the intake and offboarding controls, then sits on the buyer’s call and gives the answer; if the review is headed toward an audit, that same inventory is the first evidence request in a SOC 2 program. Kickoff is the week the contract is signed, and your first 8 hours are free.
Roei has presented this to rooms of cybersecurity people who told him hardware isn’t their problem. Listen to the 46 minutes on episode 103 and decide for yourself. My vote: it’s ours. It has always been ours. We just kept reading the sticker.
Zero trust and hardware provenance frequently asked questions
- Does zero trust cover hardware?
- On paper, yes. NIST Special Publication 800-207 lists as its fifth tenet that the enterprise monitors and measures the integrity and security posture of all owned and associated assets, and the Cybersecurity and Infrastructure Security Agency's Zero Trust Maturity Model makes Asset and Supply Chain Risk Management one of the four functions of its Devices pillar. In practice most zero trust programs verify a management agent running on the device and never verify the device itself, which is the gap Roei Ganzarski means when he says your zero trust is running on a sticker.
- What does "your zero trust is running on a sticker" mean?
- It means the hardware underneath every zero trust control is trusted for one reason: a label that names a manufacturer and a country of origin. Identity, device posture, network and data are checked on every request. The switch, server or laptop those checks run on was accepted on delivery because the box looked right. Counterfeit or tampered hardware can carry a backdoor, listen in, or alter data, and the software layer above it has no way to know.
- What is hardware provenance?
- Hardware provenance is documented, verifiable knowledge of where a physical device came from and what happened to it on the way to you: who made it, which channel sold it, whether it was opened or altered in transit, and whether the object in your rack is the object the manufacturer shipped. Purchase records and serial numbers establish the chain of custody; cryptographic attestation from the device's own silicon, or an optical fingerprint of the object, establishes that the thing itself is genuine.
- What is the difference between counterfeit and gray market hardware?
- A counterfeit is a fake object that was not made by the company on the label. A gray market product is a genuine object that moved through a channel the manufacturer never authorized, so it arrives with no warranty record, no support entitlement and an unknown history. Roei Ganzarski adds a third category from his customers' experience: a manufacturer's own distributors are sometimes the ones caught moving product outside the authorized chain. All three carry an identical label.
- How does Alitheon's FeaturePrint identify a physical object?
- No machine makes the same thing twice, so every design engineer publishes a tolerance band, and everything inside it passes quality control and looks identical. FeaturePrint photographs the surface with an off-the-shelf industrial camera or a phone, reads the differences that remain inside that band, and turns them into a digital identity of 500 kilobytes or less. Alitheon calls it biometrics for things. On the show Roei Ganzarski put the odds of two items sharing a signature at one in six and a half trillion and said there is no machine learning in the math; Alitheon markets the product as optical AI, and both describe the same system.
- What happened in the AOG Technics aircraft parts case?
- AOG Technics, a London distributor, sold aircraft engine parts with forged Authorised Release Certificates, the paperwork that certifies a part's origin and condition. A TAP Air Portugal mechanic caught it in 2023 by comparing a part marked new against its certificate. CFM International identified 126 affected engines, the UK Serious Fraud Office charged the director with fraudulent trading covering January 2019 to July 2023, and in February 2026 he was sentenced to four years and eight months after admitting more than 60,000 parts had been sold with forged certificates. The FAA found no unsafe condition. Nothing in the scheme was physically counterfeited; the forgery was the paperwork.
- How can a startup verify that a laptop or network switch is genuine?
- Buy only through authorized channels and register your reseller with Apple Business Manager or your OEM so devices arrive already tied to your account. Log every serial at receiving, before the owner opens the box. Enroll with Automated Device Enrollment or Windows Autopilot before first login. Then ask the silicon: Apple's Managed Device Attestation, TPM measured boot on Windows, and Cisco's SUDI certificate check (show platform sudi certificate) each prove the device is the one the manufacturer built. Reconcile the inventory against your identity provider monthly.
- What does SOC 2 require for hardware asset inventory?
- The SOC 2 Trust Services Criteria expect an entity to identify, inventory, classify and manage its information assets (a point of focus under CC6.1) and to assess and manage risks associated with vendors and business partners (CC9.2). ISO/IEC 27001:2022 asks for the same in A.5.9 and A.5.21, and CIS Control 1 is entirely about inventory and control of enterprise assets. None of them require optical fingerprinting; all of them require that you can say, with evidence, what hardware you own and where it came from.
- What is a hardware bill of materials (HBOM)?
- A hardware bill of materials lists the components inside a product, the way a software bill of materials lists the libraries inside an application. The Cybersecurity and Infrastructure Security Agency published an HBOM Framework for Supply Chain Risk Management in September 2023 so vendors and buyers can describe components consistently. It is a communication format, not a detection tool: an HBOM tells you what should be inside the box, and something else has to confirm that it is.