Zero Trust Security in Procurement

Zero Trust Security in Procurement

I recently came across an article named Zero Trust Security and it’s related to Cyber Security framework. This framework assumes that all network traffic is potentially malicious and that no user or device can be trusted without verification.

I’m not going to say anything about Zero Trust Security from a Cybersecurity perspective as it’s not my domain. But taking up the concept of Zero Trust Security, I’m trying to write my views about the importance of the Zero Trust concept in Procurement.

What’s zero trust security in the IT field? Nowadays in any large corporates, you may see that there are many site controlling tools like Zscaler, Palo Alto, Crowd strike, etc. imparted in their environment, does it mean that companies don’t trust employees?

No, it’s not distrust of employees! But the company authorities or IT/Infosec team is aware that while the employee needs to visit various websites to gather some information to fulfill their duties, where they may visit few unknown websites from where there are chances of getting malicious attacks on user’s PC and ultimately company environment which may ruin entire network. To avoid damage to the entire network, such kind of tools are imparted in the network environment to prevent employees from reaching such suspicious sites.

Similarly in Procurement, during discussions between Supplier and Buyer, suppliers agree on many more terms to grab the order but when the time comes to execute PO or an agreement, it’s found that many of the suppliers don’t agree to include few of the terms agreed verbally.

It’s necessary to document every term discussed between the buyer and the seller. That term may be related to the pricing of the product, the scope of work, specifications of products, Transport arrangement, insurance part, Payment Terms, delivery timeline, penalties in case of delay of delivery or execution of a project, etc.

It’s not that the buyer is not having trust in the seller, but the fact is that the seller may not get involved in the delivery or execution of services, and verbally agreed information may not have passed to the delivery team or execution team. Similarly, buyers may not get involved in receiving delivery or getting services directly from supplier organizations. Also deviating in agreed terms may impact largely to both parties. Hence execution and receiving teams should have written information available to them on what’s agreed between both parties.

So, in a nutshell, documentation of each term in the PO or Agreement is essential to have proper accountability.

However, I’m not sure why, but many supplier organizations though agree to many of the terms verbally to grab the order, take an objection to include few terms in the PO or Agreement that are particularly related to indemnity, agreed payment terms, Penalties or Limitations of Liability, etc. This trend is there for small fabrication kinds of organizations to large OEMs.

I believe there should be fairness in the deal and hence there should be Zero Trust Security built into PO and Agreement.

Usman Javaid.

Category.Manager Procurement@Bunnys Ltd. X-Master Group/X-Interwood/X-Schazoo Pharma's.

1 年

very informative.

Pramod Sonmale

CEO & DIRECTOR at AMAZURE TECHNOLOGIES PVT LTD

1 年

Great highly appreciated thinking differently, first time I have come across any procurement leadership taking intrest in leveraging cyber security technology concept .

要查看或添加评论,请登录

Mahesh Kulkarni的更多文章

  • The Art of Storytelling in Procurement.

    The Art of Storytelling in Procurement.

    Transforming the Procurement Process Through Narrative I was going thru few articles on Storytelling, how it helps…

    2 条评论
  • A Journey Through Vision in the Dark

    A Journey Through Vision in the Dark

    An Enlightening Experience in Ahmedabad Recently, I had the unique opportunity to visit a remarkable place called…

    1 条评论
  • Gen AI and Procurement: A New Paradigm

    Gen AI and Procurement: A New Paradigm

    I’m writing this informative article for my fellow friends in Procurement fraternity. With the release of ChatGPT in…

    3 条评论
  • Diversity & Inclusion

    Diversity & Inclusion

    Nowadays Diversity and Inclusion are becoming an important subject for all Corporates. Recently I came across the…

    2 条评论
  • Monte Carlo simulation

    Monte Carlo simulation

    Recently I read one of the good articles about Monte Carlo Simulation and today I am going to write something about…

  • Organization’s Resilience Strategy through Procurement

    Organization’s Resilience Strategy through Procurement

    In the past three years, during COVID days, we have witnessed so many waves of disruption causing survival issues for…

    1 条评论
  • MoCoW Analysis

    MoCoW Analysis

    MoSCoW Analysis I recently came across the MoSCoW Analysis technique. Since I was not familiar with this terminology…

  • Regression Analysis in Procurement

    Regression Analysis in Procurement

    Regression Analysis in Procurement Few days ago I came across this terminology called Regression Analysis and I was…

    2 条评论
  • Procrastination in PROCUREMENT

    Procrastination in PROCUREMENT

    Impact of Procrastination on Procurement Success Did you ever check whether procrastination actually costs us more? You…

    4 条评论
  • Procurement Risk Management

    Procurement Risk Management

    We as Procurement professionals faces lots of Procurement risks while working in corporates and every one struggle for…

    5 条评论

社区洞察

其他会员也浏览了