What does the Federal Guidance on Securing the Software Supply Chain Mean for Developers?

General News

Summary

It is the result of investigations into Solar Winds, an attack which revealed the need to create a set of industry and government evaluated best practices focusing on the needs of the software supplier. In response to ongoing attacks against the infrastructure of the United States, the White House released an Executive Order on Improving the Nation’s Cybersecurity (EO 14028) in 2021. “Developers should perform unit- and system-level security tests that are validated by QA,” the report states. “This allows QA to perform further security testing to cover a broader and deeper set of tests with less duplication of effort.” In addition to Static Analysis and Software Composition Analysis, the report explicitly cites: “Fuzzing should be performed on all software components during development to ensure that they exhibit expected behavior with different inputs. Results should be documented, and any anomalies or vulnerabilities should be addressed.” In another blog we’ll take a deeper look at NIST 800-218, which is heavily referenced in the Securing The Software Chain series part one.

Classifications

industries
No industries detected
applications
AI & Machine learning

AskAI Classifications

Labels
No AI classifications detected

Linked Companies

ForAllSecure
$1M to $5M