Make-or-Buy Analysis

A structured approach to collect and organize product requirements, then evaluate viable options to decide whether to purchase the item from an external vendor or manufacture it within the organization.

Key Points

  • Compares external procurement versus in-house production to meet project needs.
  • Assesses total lifecycle costs, including acquisition, operations, maintenance, and disposal.
  • Considers schedule, quality, risk, capacity, and organizational expertise.
  • Guides the procurement strategy and documentation in the procurement management plan.

Example

A hardware project requires custom metal brackets. The team gathers specifications, estimates internal fabrication effort, and requests quotes from suppliers. Analysis shows a qualified vendor can deliver sooner with lower total cost and acceptable quality, so the project opts to buy rather than make.

PMP Example Question

While planning procurements, the team compiles product requirements and compares building a component internally versus purchasing a commercial alternative to meet a tight deadline. What technique are they using?

  1. Make-or-buy analysis
  2. Bidder conference
  3. Source selection criteria
  4. Procurement performance review

Correct Answer: A — Make-or-buy analysis

Explanation: Make-or-buy analysis evaluates whether to procure from an external supplier or produce in-house by comparing requirements, costs, schedule, risks, and capabilities.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course