From the Fall 2026 Issue

The Procurement Decision: Where Cybersecurity Governance Begins

Bobbie Stempfley
Vice President | Dell Technologies | Former CIO, Defense Information Systems Agency (DISA)

Dr. Ray A. Letteer, DSc
Former Director of Operations Risk Assessment, Office of the DoD Chief Information Officer, Former Chief Information Security Officer (CISO), Authorizing Official (AO) | United States Marine Corps

Henry J. Sienkiewicz
Adjunct Faculty | Georgetown and George Washington Universities | Former CIO, Defense Information Systems Agency (DISA)

Keith K. Nakasone
Independent Consultant | ProcureTech Consulting, LLC

Every significant cybersecurity incident begins with a trust decision.

Long before an adversary exploits a vulnerability, before a System Owner assumes operational responsibility, before an Authorizing Official accepts residual risk, and before a Mission Owner weighs cyber risk against mission necessity, someone decided to trust an external capability. That decision may have appeared routine—a software acquisition, cloud service, managed services agreement, artificial intelligence platform, or technology refresh—but it fundamentally changed the organization’s security posture. Procurement does more than acquire technology; it establishes new trust relationships, introduces operational dependencies, and creates governance responsibilities that would persist throughout the capability’s lifecycle.

Procurement has traditionally been viewed as an administrative function measured by price/cost, schedule, competition, contract compliance, and vendor performance. Cybersecurity typically enters later through architecture reviews, security assessments, control implementation, and formal authorization. While these activities remain essential, they occur only after one of the enterprise’s most consequential cybersecurity decisions has already been made: the decision to incorporate an external capability into the operational environment.

Procurement should be recognized as one of the earliest cybersecurity governance functions. Organizations do not simply purchase products and services; they acquire trust. Every acquisition establishes relationships that extend beyond the prime contractor to include cloud providers, software supply chains, identity services, Application Programming Interfaces (APIs), Artificial Intelligence (AI) components, subcontractors, managed service providers, and other inherited dependencies. The practical outcome should be operational trust: justified confidence 8 that the acquired capability, supplier relationship, and supporting dependencies can be relied upon for the mission under known conditions, residual risk, and monitoring expectations.

This article builds on the preceding articles in what has become governance series. Authorization as part of the Authority To Operate (ATO) process argued that authorization is an exercise in executive judgment rather than administrative compliance (Letteer & Sienkiewicz, 2026). The Federal System Owner in the Age of Continuous Authorization described system ownership as continuous stewardship of operational trust (Stempfley, Letteer, & Sienkiewicz, 2026a). Stewards of Risk reframed the Authorizing Official as the executive responsible for determining whether available evidence justifies accepting residual risk in pursuit of mission objectives (Stempfley, Letteer, & Sienkiewicz, 2026b).

This article extends that governance chain one step earlier. Before organizations can govern systems, they must first decide which technologies, suppliers, and relationships they are willing to trust. Procurement does not authorize the system, but it creates the first evidence, assumptions, obligations, and dependency record that later authorization decisions must rely upon. Procurement is not simply the beginning of acquisition; it is the beginning of cybersecurity governance.

Procurement As The First Governance Decision

Cybersecurity governance does not begin when a system is deployed. It begins when an organization determines what capabilities it requires, which external relationships it is willing to establish, and what degree of uncertainty it is prepared to accept in pursuit of its mission. Procurement is  not simply an acquisition milestone; it is the enterprise’s first governance decision.

Traditional acquisition models often separate mission planning, procurement, engineering, cybersecurity, operations, and authorization into distinct activities performed by different organizations. In practice, they form a continuous governance chain in which each decision inherits the assumptions established by the one before it.

Mission requirements define the capabilities needed to achieve organizational objectives. Procurement transforms those requirements into relationships with external organizations. Those relationships establish technical and operational trust that operational teams integrate into enterprise workflows. Authorizing Officials then determine whether sufficient evidence exists to accept the resulting residual risk, while continuous monitoring evaluates whether the assumptions supporting those decisions remain valid as technologies, suppliers, and threats evolve.

Figure 1: The Procurement Governance Chain
Figure 1: The Procurement Governance Chain

Procurement occupies a unique position within this lifecycle because it bridges organizational intent and operational reality. Decisions regarding supplier selection, contractual obligations, architectural transparency, operational evidence, and supply-chain relationships shape every governance activity that follows. Weak procurement decisions become inherited governance problems regardless of how well downstream security controls are implemented. Procurement therefore creates the first record of trust: what the organization believed, what evidence it reviewed, what obligations it imposed, and what assumptions later governance roles inherit.

Federal acquisition policy already reflects this lifecycle perspective. FAR Part 7 treats acquisition planning as more than a transactional event, while FAR Parts 10, 39, and 40 emphasize market research, planning, information security, supply chain security, and risk management. FAR Part 40 specifically recognizes information security and supply chain security as acquisition considerations that extend beyond traditional information technology procurement. The DFARS extends through requirements for covered defense information, cyber incident reporting, information technology acquisitions, and cybersecurity compliance requirements associated with the Cybersecurity Maturity Model Certification (CMMC) program. (48 C.F.R. §§ 7, 10, 39, 40; 48 C.F.R. ch. 2; 32 C.F.R. Part 170). Although commonly treated as acquisition requirements, these provisions also operate as governance mechanisms by establishing expectations for transparency, accountability, evidence, and stewardship throughout the life of an acquired capability.

The rapid adoption of cloud computing, software-as-a-service, managed services, and, now, artificial intelligence reinforces this governance perspective. Organizations rarely establish a relationship with a single supplier. Instead, procurement introduces interconnected ecosystems that include cloud providers, software supply chains, identity services, APIs, AI capabilities, subcontractors, and managed service providers. These relationships continue to evolve through software updates, infrastructure changes, acquisitions, and new integrations, making procurement the starting point for governance responsibilities that persist long after contract award.

Cybersecurity leaders should view procurement not as an administrative prerequisite but as the point at which organizational trust first becomes operational. Questions concerning architecture, supply-chain resilience, AI governance, contractual transparency, evidence, and accountability should be addressed before technologies become enterprise dependencies.

Procurement extends the governance chain upstream. Before organizations can govern systems, they must first govern the decisions that determine which systems—and which trust relationships—become part of the enterprise.

Procurement is not merely the beginning of acquisition. It is the beginning of cybersecurity governance.

The Invisible Stack Enters Through Procurement

The technologies organizations procure today bear little resemblance to the standalone products of the past. Enterprises no longer acquire isolated applications or self-contained information systems. Instead, they acquire interconnected digital ecosystems composed of cloud infrastructure, Software-as-a-Service (SaaS) platforms, identity providers, APIs, AI capabilities, open-source software, managed services, and evolving networks of subcontractors and technology partners. Procurement establishes far more than a contractual relationship with a vendor—it establishes participation in an ecosystem of inherited trust and operational dependency (NIST, 2022a, 2022b).

This ecosystem represents what The Invisible Stack describes as the technical, operational, organizational, and governance relationships that enable modern digital capabilities but frequently remain unseen until they fail (Sienkiewicz, 2026a). Procurement documents identify suppliers, pricing, and contractual deliverables. Enterprise architecture diagrams describe systems and interfaces. Neither fully reveals the inherited dependencies that ultimately determine operational resilience.

Organizations increasingly purchase capabilities delivered through layers of external relationships rather than directly through a single supplier. A cloud collaboration platform, for example, may rely on multiple cloud regions, externally managed identity services, content delivery networks, API gateways, managed databases, telemetry platforms, software libraries, and geographically distributed support organizations. While these dependencies are largely invisible during acquisition, they become highly visible during service disruptions, supply-chain compromises, or incident response (NIST, 2022b).

The same pattern extends across modern digital services. SaaS platforms depend upon third-party authentication, analytics, payment services, APIs, open-source frameworks, and cloud-hosted infrastructure. API integrations connect organizations to financial institutions, logistics providers, government services, and business partners, extending enterprise boundaries well beyond traditional network perimeters. AI capabilities increasingly rely on externally hosted foundation models, cloud inference services, retrieval architectures, vector databases, and continuously evolving machine learning pipelines. Open-source software introduces additional dependencies maintained outside both the vendor’s and the customer’s direct control, while subcontractors and managed service providers further expand operational relationships that could change throughout the contract lifecycle (Executive Office of the President, 2021; NIST, 2022c; NIST, 2023; NIST, 2024a).

Figure 2: The Invisible Stack Introduced Through Procurement
Figure 2: The Invisible Stack Introduced Through Procurement

Collectively, these dependencies form the enterprise’s inherited operating environment. Most are neither owned nor directly controlled by the acquiring organization, yet each influences availability, resilience, security, and governance. As providers update software, retrain AI models, migrate cloud infrastructure, introduce new subcontractors, or modify service architectures, the organization’s effective dependency structure changes—even when no new procurement action occurs.

This is the governance significance of The Invisible Stack. Hidden dependencies should not first be discovered during implementation or incident response; they should be considered during procurement. Questions regarding cloud hosting, identity services, AI components, software supply chains, APIs, open-source software, subcontractor transparency, and operational support are not simply matters of technical due diligence. They are decisions about organizational trust that shape future resilience.

Procurement becomes the point at which organizations intentionally decide which invisible relationships they are willing to inherit. Today’s acquisition decisions establish tomorrow’s operational dependencies—and ultimately tomorrow’s governance responsibilities (Sienkiewicz, 2026b).

Evidence Is Not Trust

Modern procurement organizations have access to more cybersecurity evidence than at any point in history. Vendors routinely provide security questionnaires, System and Organization Controls (SOC) reports, ISO/IEC 27001 certifications, FedRAMP authorization packages, Software Bills of Materials (SBOMs), penetration test summaries, Cybersecurity Maturity Model Certification (CMMC) assessments, vulnerability disclosures, and increasingly, documentation describing the governance of artificial intelligence systems. Collectively, these artifacts provide valuable insight into supplier cybersecurity practices and improve organizational transparency.

What they do not provide is certainty.

And, cybersecurity is fundamentally a discipline of decision-making under conditions of uncertainty. Evidence reduces uncertainty; it does not eliminate it (Sienkiewicz, 2026). Every procurement decision remains an exercise in executive judgment. The question is not whether evidence exists, but whether the available evidence justifies establishing a long-term trust relationship.

This distinction matters because organizations often confuse documentation with assurance. Procurement teams often review extensive security documentation while technical experts evaluate architectures, security controls, and assessment results. Each contributes valuable insight. None answers the governance question:

Should the organization trust this relationship?

That decision cannot be delegated to an auditor, certification body, assessor, or supplier. It remains an executive judgment informed by evidence but accountable for the consequences of the decision.

The most common procurement artifacts illustrate this distinction. A SOC 2 Type II report provides assurance that specified controls operated effectively during a defined assessment period. An ISO/IEC 27001 certification demonstrates the existence of a mature information security management system. FedRAMP authorizations provide rigorous evidence regarding cloud security controls while recognizing that agencies remain responsible for determining mission suitability. CMMC establishes confidence that defense contractors have implemented cybersecurity practices appropriate to protecting Controlled Unclassified Information. The Department of War’s pause in advancing CMMC Level 2 third-party assessment requirements underscores that formal certification timelines may shift; however, CMMC Level 1 self-assessment requirements remain in effect, and procurement officials must still evaluate whether the available evidence supports a defensible trust decision. (U.S. Department of War, 2026)

SBOMs improve software supply-chain transparency, and penetration testing demonstrates what qualified assessors identified under specific conditions. AI governance documentation provides insight into model development and oversight but cannot guarantee future model behavior as systems evolve (Executive Office of the President [EOP], 2021; FedRAMP, 2024; International Organization for Standardization [ISO}, 2022; NIST, 2022a, 2022b, 2023; U.S. Department of Defense [DoD], 2024).

Each artifact contributes valuable evidence. None transfers accountability.

Evidence is cumulative, but judgment remains singular. Organizations should seek multiple independent sources of evidence because each reduces uncertainty from a different perspective. Yet no combination of reports, certifications, assessments, or contractual representations eliminates the need for executive judgment. Responsibility for establishing trust always remains with the acquiring organization.

Viewed this way, procurement is not an exercise in collecting documentation but in evaluating whether the available evidence provides sufficient confidence to justify an enduring trust relationship. The objective is not to assemble the largest possible compliance package; it is to gather sufficient, credible, and decision-relevant evidence to support a defensible governance decision.

The essential procurement question becomes:

How does this evidence improve our confidence in the trust relationship we are about to establish?

When procurement shifts its focus from collecting documentation to evaluating evidence, cybersecurity becomes more than a compliance exercise. It becomes a disciplined process of governance in which evidence informs judgment but never replaces accountability.

A Governance Framework: The Six Duties Of The Cyber-Informed Procurement Official

If procurement represents the first governance decision in the cybersecurity lifecycle, procurement professionals require a framework that extends beyond traditional acquisition responsibilities. Existing guidance appropriately addresses competition, contracting, market research, pricing, and performance management. Those disciplines remain essential, but they do not fully address the governance responsibilities created by modern technology acquisition.

Six duties define the cyber-informed procurement official. Together, these duties reposition procurement from a transactional business function to a strategic governance capability that supports organizational resilience throughout the technology lifecycle.

1. Frame The Mission

Cyber-informed procurement begins by understanding why the organization needs a capability rather than what it intends to purchase. Every acquisition should support a mission, improve operational performance, or reduce organizational risk.

Figure 3: The Six Duties of the Cyber-Informed Procurement Official
Figure 3: The Six Duties of the Cyber-Informed Procurement Official

Mission framing asks questions that extend beyond procurement:

  • What operational capability is being enabled?
  • What mission depends upon it?
  • What are the consequences if it becomes unavailable, compromised, or behaves unexpectedly?
  • Which business functions rely upon it?

These questions shift procurement from comparing products by cost and functionality to evaluating them according to mission consequence. A collaboration platform supporting routine administration presents a different governance challenge than one supporting emergency operations. Likewise, an AI assistant for internal productivity requires different oversight than one supporting operational decision-making.

Mission importance—not technical complexity—should determine the depth of cybersecurity governance (NIST, 2022a).

2. Expose Hidden Dependencies

Every acquisition establishes relationships that extend beyond the organization identified in the contract. Cloud providers, identity services, managed services, APIs, AI platforms, software supply chains, and subcontractors collectively form the organization’s inherited dependency structure—the practical expression of The Invisible Stack (Sienkiewicz, 2026a).

Cyber-informed procurement looks beyond the visible supplier. It asks where data resides, how identities are managed, which cloud providers host services, which APIs enable business processes, how software is maintained, and which organizations become operational dependencies through the acquisition.

The objective is not to eliminate complexity but to make it visible before it becomes operational risk. Organizations cannot govern relationships they do not recognize.

3. Evaluate Evidence

Cyber-informed procurement depends upon evidence without confusing evidence with certainty.

Security questionnaires, SOC reports, FedRAMP authorizations, ISO/IEC 27001 certifications, SBOMs, penetration tests, CMMC assessments, vulnerability disclosures, and AI documentation each provide valuable insight. None eliminates uncertainty.

The critical questions become:

  • What confidence does this evidence provide?
  • What assumptions remain unresolved?
  • What additional evidence is required?
  • What risks still require executive judgment?

Evidence supports decisions. It never replaces accountability (Sienkiewicz, 2026b).

4. Shape Governance

Governance begins before systems are deployed.

Contract language establishes the mechanisms that future System Owners, cybersecurity professionals, and Authorizing Officials will depend upon. Notification requirements, audit rights, evidence preservation, vulnerability disclosure, logging, software updates, subcontractor transparency, incident reporting, AI governance, and lifecycle support are not administrative clauses; they are governance instruments. The practical artifacts are straightforward: dependency disclosures, supplier security evidence, SBOMs where appropriate, incident notification terms, subcontractor transparency, audit or review rights, logging expectations, AI governance documentation, change notification requirements, and reassessment triggers.

Well-designed contracts also recognize that technology evolves. Cloud services change, AI capabilities expand, software architectures mature, and supplier ecosystems shift. Procurement should establish governance mechanisms that remain effective throughout the relationship rather than assuming cybersecurity obligations end at contract award.

5. Document Judgment

Organizations frequently preserve contracts and compliance documentation while losing the reasoning behind the decisions that created them.

Cyber-informed procurement documents judgment, not simply compliance.

Decision records should explain:

  • why a supplier was selected;
  • what alternatives were considered;
  • what evidence informed the decision;
  • what assumptions remained unresolved;
  • who accepted residual risk; and
  • what future conditions should trigger reassessment.

These records preserve institutional memory, support audits and investigations, and demonstrate that procurement decisions were deliberate, evidence-based, and governed rather than merely compliant.

6. Monitor For Drift

Procurement does not end when a contract is awarded. It begins an ongoing governance relationship.

Suppliers acquire competitors. Cloud infrastructure changes. AI models evolve. APIs expand. Software architectures mature. Missions, regulations, and threat environments also change. Over time, these changes create governance drift—the gradual divergence between the assumptions supporting the original procurement decision and current operational reality.

Cyber-informed procurement contributes to continuous governance by participating in supplier reviews, evaluating architectural changes, reviewing updated evidence, reassessing inherited dependencies, and ensuring significant changes receive appropriate executive attention.

Monitoring for drift completes the governance chain. Procurement establishes trust. System Owners govern operational capability. Authorizing Officials evaluate residual risk. Continuous monitoring determines whether the assumptions supporting those decisions remain valid.

Procurement is not a discrete acquisition activity but an enduring governance function (Sienkiewicz, 2026b)

Procurement Within the Continuous Governance Chain

The preceding articles in this governance series argue that cybersecurity governance is best understood as a continuous process of organizational judgment rather than a sequence of isolated technical activities. Procurement extends that governance chain upstream by recognizing that every subsequent governance decision inherits the trust relationships established during acquisition.

Viewed as a governance lifecycle, each role performs a distinct responsibility while building upon the decisions of those before it.

  • Procurement establishes trust relationships.
  • System Owners govern operational capability.
  • Authorizing Officials determine whether available evidence justifies accepting residual risk.
  • Mission Owners determine whether that residual risk remains acceptable in pursuit of organizational objectives.

None of these responsibilities exist in isolation. Procurement professionals do not authorize systems, Authorizing Officials do not negotiate contracts, and Mission Owners do not conduct security assessments. Yet each depends upon the quality of decisions made earlier in the governance chain. Weak procurement decisions increase operational complexity for System Owners. Poor operational governance reduces the quality of evidence available to Authorizing Officials. Weak authorization decisions ultimately increase uncertainty for Mission Owners responsible for balancing mission effectiveness against organizational risk.

The governance chain functions less as a hierarchy than as a relay. Each participant receives a partially completed decision, strengthens it through evidence and stewardship, and transfers responsibility to the next governance role. Organizational resilience depends not upon any single decision, but upon the continuity of judgment across the entire technology lifecycle.

This perspective also reflects the evolution of federal acquisition policy. FAR Parts 7, 9, 10, 39, and 40 emphasize lifecycle planning, contractor responsibility, market research, information security, supply chain security, and risk management rather than isolated purchasing actions (48 C.F.R. §§ 7, 9, 10, 39, 40). FAR Part 40 reflects the growing recognition that information security and supply chain security are acquisition concerns as well as operational concerns. The DFARS extends these principles by recognizing that cybersecurity obligations continue throughout contract performance.  Recent DFAR changes implementing the CMMC program establish cybersecurity requirements as contractual obligations tied to contractor eligibility, assessment, affirmation, and continuous compliance.  CMMC reinforces that protecting defense information depends upon sustained organizational capability rather than on-time compliance. (48 C.F.R. ch. 2; U.S. DoD, 2024).

Figure 4: Cyber-Informed Procurement Requires Cross-Functional Governance
Figure 4: Cyber-Informed Procurement Requires Cross-Functional Governance

Broader federal cybersecurity guidance reaches the same conclusion. NIST SP 800-161 Rev. 1 emphasizes cybersecurity supply-chain risk management across the system lifecycle, and Executive Order 14028 highlights software supply-chain transparency and secure software development as foundational elements of national cybersecurity (EOP, 2021; NIST, 2022b). These frameworks point in the same direction: acquisition has evolved beyond purchasing technology toward governing digital ecosystems.

The challenge is no longer simply acquiring capable products. It is establishing trustworthy relationships that remain transparent, governable, and resilient throughout their operational life.

Cyber-informed procurement does not introduce a new governance model. Rather, it provides a governance lens through which existing acquisition policy can be understood as the first stage of continuous cybersecurity governance.

The Future Of Cyber-Informed Procurement

Federal procurement is evolving from a document-driven acquisition process to a continuously informed governance function. As technology ecosystems become more dynamic, procurement decisions will increasingly rely on current operational evidence rather than static compliance artifacts collected at a single point in time. Continuous Authorization to Operate (cATO), SBOMs, secure software attestations, automated vulnerability reporting, and continuous supplier monitoring all point toward the same shift: procurement strategies must support ongoing transparency rather than one-time certification (EOP, 2021; NIST, 2022a, 2022b, 2022c; U.S. DoD Chief Information Officer [CIO], 2024).

Artificial intelligence will accelerate this change. AI-enabled tools are able to assist acquisition professionals by identifying supply-chain dependencies, comparing security documentation, evaluating software provenance, detecting contractual inconsistencies, and highlighting emerging supplier risks. At the same time, procurement officials will increasingly acquire AI-enabled products whose behavior, training data, and supporting infrastructure continue to evolve after deployment. Both uses reinforce the need for continuous evidence, transparency, and executive oversight throughout the technology lifecycle (NIST, 2023).

These developments point toward a broader shift in acquisition philosophy. Procurement will become progressively more evidence-driven, continuously informed, and integrated with enterprise cybersecurity governance. Rather than representing a discrete event before system implementation, acquisition will function as the first stage of an enduring governance relationship that connects procurement, system ownership, authorization, continuous monitoring, and mission execution.

Conclusion

Cyber-informed procurement is a strategic governance capability essential to enterprise resilience, national security, and operational trust.

Cybersecurity governance begins long before systems enter production. It begins when organizations decide whom to trust, what dependencies they are willing to inherit, and how those decisions will be justified over time.

Procurement should be incorporated as one of the earliest governance functions in cybersecurity. By framing mission needs, exposing hidden dependencies, evaluating evidence, shaping governance, documenting judgment, and monitoring for drift, procurement professionals become active participants in organizational resilience rather than passive participants in administrative acquisition.

Viewed through this lens, procurement is not the beginning of a contracting process; it is the beginning of an enduring governance relationship. Every subsequent governance activity, from system ownership and authorization through continuous monitoring and mission execution, builds upon the trust decisions established during acquisition. The rise of artificial intelligence only strengthens this point: procurement must now govern not only systems and suppliers, but also models, data, training pipelines, inference services, and behaviors that may change after award.

This article completes the fourth installment of our governance series and naturally leads to the next discussion: the Mission Owner, whose responsibility is to determine whether those cyber-informed governance decisions continue to support mission success as operational conditions evolve. lock

References

Executive Office of the President. (2021, May 12). Executive Order 14028: Improving the Nation’s cybersecurity. https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity

Federal Risk and Authorization Management Program. (2024). FedRAMP. https://www.fedramp.gov/

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org

National Institute of Standards and Technology. (2022a). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy (Special Publication 800-37 Rev. 2). U.S. Department of Commerce.

National Institute of Standards and Technology. (2022b). Cybersecurity supply chain risk management practices for systems and organizations (Special Publication 800-161 Rev. 1). U.S. Department of Commerce.

National Institute of Standards and Technology. (2022c). Secure software development framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (Special Publication 800-218). U.S. Department of Commerce.

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce.

National Institute of Standards and Technology. (2024). Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce.

Letteer, R, & Sienkiewicz, H. J., The ATO Bottleneck: Rethinking Responsibility and Enabling Automation, U.S. Cybersecurity Magazine, Winter 2026.

Stempfley, R.,  Letteer, R, & Sienkiewicz, H. J. (2026a). The Federal System Owner in the Age of Continuous Authorization, U.S. Cybersecurity Magazine, Summer 2026

Stempfley, R.,  Letteer, R, & Sienkiewicz, H. J. (2026b). Stewards of Mission Risk: The Evolving Role of the Authorizing Officials (AO), U.S. Cybersecurity Magazine, Spring 2026

Sienkiewicz, H. J. (2026a). The Invisible Stack: Structure, behavior, and judgment in complex systems. Institute for Cyber Executive Education.

Sienkiewicz, H. J. (2026b). Cybersecurity As judgment: A student guide to risk, systems, governance, and decision-making. Institute for Cyber Executive Education, 2026.

U.S. Department of Defense. (2026). Defense Federal Acquisition Regulation Supplement, including Subpart 204.75, Cybersecurity Maturity Model Certification (48 C.F.R. ch. 2). https://www.acquisition.gov/dfars/

U.S. General Services Administration, Department of Defense, & National Aeronautics and Space Administration. (2026). Federal Acquisition Regulation, including Part 40, Information Security and Supply Chain Security  (48 C.F.R. ch. 1). https://www.acquisition.gov/far

Bobbie Stempfley, Dr. Ray A. Letteer, DSc, Henry J. Sienkiewicz, Keith K. Nakasone

Leave a Comment