Software Supply Chain Security: Securing the End-to-end Supply Chain for Software, Firmware, and Hardware
Author: Cassie Crossley (Author), Emily Heath (Foreword)
Publisher finelybook 出版社: Oreilly & Associates Inc
Edition 版本: 1st
Publication Date 出版日期: 2024-03-12
Language 语言: English
Print Length 页数: 219 pages
ISBN-10: 1098133706
ISBN-13: 9781098133702
Book Description
Trillions of lines of code help us in our lives, companies, and organizations. But just a single software cybersecurity vulnerability can stop entire companies from doing business and cause billions of dollars in revenue loss and business recovery. Securing the creation and deployment of software, also known as software supply chain security, goes well beyond the software development process.
This practical book gives you a comprehensive look at security risks and identifies the practical controls you need to incorporate into your end-to-end software supply chain. Author Cassie Crossley demonstrates how and why everyone involved in the supply chain needs to participate if your organization is to improve the security posture of its software, firmware, and hardware.
With this book, you’ll learn how to:
- Pinpoint the cybersecurity risks in each part of your organization’s software supply chain
- Identify the roles that participate in the supply chain—including IT, development, operations, manufacturing, and procurement
- Design initiatives and controls for each part of the supply chain using existing frameworks and references
- Implement secure development lifecycle, source code security, software build management, and software transparency practices
- Evaluate third-party risk in your supply chain
Review
— Kate Stewart
Vice President of Dependable Embedded Systems, The Linux Foundation
“During a time of ever increasing threats to our systems, this book serves as a practical guide for any organization looking to include Software Supply Chain Security as part of their risk management program.”
— Grant Schneider
Former US Federal Chief Information Security Officer
“Cassie has been a pioneer in advocating for and advancing SBOM, particularly in critical infrastructure. This volume is a critical contribution that underscores the need for software transaprency, and highlights paths to implementation.”
— Dr. Allan Friedman
SBOM Champion
“Cassie’s book is the most thorough, practical, organized, and actionable supply chain advice I’ve ever received. Via frameworks and detailed plans this book lays out exactly what to do to ensure your entire product supply chain (physical or digital) is reliably secure.”
— Tanya Janca (SheHacksPurple)
Head of Community and Education; author of Bob and Alice Learn Application Security
“Cassie brings a wealth of knowledge to the topic in this book, covering relevant attack vectors, emerging frameworks, vulnerability disclosures, products, open source, third-party suppliers and navigating the complex human element, all too often overlooked in software supply chain security.”
— Chris Hughes
President & Co-Founder, Aquia; Cyber Innovation Fellow (CIF) at CISA; co-author of Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
About the Author
Cassie has held positions at Schneider Electric, Ceridian, Hewlett-Packard, McAfee, Lotus, and IBM. She has an M.B.A. from California State University, Fresno, and her Bachelor of Science degree in Technical and Professional Communication with a specialization in Computer Science from Southern Polytechnic State University (now consolidated into Kennesaw State University).