BTS #11 - SCRM and Supply Chain Security Up and Down the Stack - Steve Orrin
Supply Chain threats and industry / government initiatives like EO 14028 are driving a deeper understanding and a set of requirements for applying supply chain risk management (SCRM) and increased transparency (ex. SBOM) across the software ecosystem up and down the stack. Platform and system firmware present unique challenges for supply chain assurance from the depths of the stack.
Segment Resources: ESF: Securing the Software Supply Chain for Customers
https://media.defense.gov/2022/Nov/17/2003116445/-1/-1/0/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_CUSTOMER.PDF ESF: Securing the Software Supply Chain for Suppliers
ESF: Securing the Software Supply Chain for Developers
CISA SBOM Site https://www.cisa.gov/sbom
Show Notes: https://securityweekly.com/bts-11