Secure software supply chain risk management
With this understanding of RASIC, vendor security assessment, CIAD, the risks of OSS, and SBOMs, let’s put it all together to get a comprehensive view of secure software supply chain risk management (SSCRM).
Generally speaking, SSCRM focuses on identifying, assessing, and mitigating the risks associated with the software development life cycle (SDLC). These steps are briefly explained as follows.
Identifying the risks
The first step in SSCRM is identifying the risks in the software supply chain. An organization can start by creating a comprehensive inventory of all supply-chain-related software components used in their projects. Thus, this inventory includes all libraries, frameworks, OSS components, third-party-developed components, commercial components, external cloud services, and so on.
The organization then needs to analyze all these components in its inventory for potential weaknesses and vulnerabilities. This includes...