Home > Journey to Software Supply Chain Security eBook
Software supply chain security, operationalized in 5 stages
Software vendors have long been focused on dealing with the problem of software vulnerabilities, but software supply chain vulnerability is actually much broader, encompassing all of the code that vendors import, build and ship. In other words, the software supply chain extends across the entire software development lifecycle (SDLC), including all of the processes and systems that interact with it. Therein lies the problem: the need for software vendors to secure everything, whereas bad actors need only a single weak link to exploit.
Fear not, we have the roadmap to guide you through the journey of securing your software supply chain.
JUNE 11, 2023: Executive Order Mandate 14028 goes into effect, complete with legal repercussions for those who don’t comply.
In response to the growing threat of software supply chain attacks, as well as the reluctance of software vendors to embrace a security-first mindset, the US government has taken the exceptional step of imposing supply chain security requirements. Effective from June 2023, any vendor of software deployed at (or even coming in contact with systems at) US government agencies or departments must comply or risk losing their contract. While the guidelines are extensive, key requirements for software vendors include:
- SBOMs – vendors must provide a machine-readable list of all the components that make up their software application, including third party libraries and integrations.
- Secure Software Development – vendors must adopt secure software development best practices, starting with detecting and resolving security vulnerabilities
Get The eBook Journey To Supply Chain Security
Start now to get compliant with EOM 14028 and the SLSA 1.0 framework
Attestations
Signed attestations provide a critical piece of the EOM and SLSA security framework puzzle.
SBOMs (Software Bill of Materials)
Provide auditable trails on who did what, when.
Provenance
Enable machine-readable audit trails for your builds.