Management of Your Software Supply Chain—A Hidden TPRM Vulnerability For All
Summary
So, here’s a question: “How do you secure and validate the integrity of promoted service packs, updates, and upgrades?” What controls do you have in place to assure the software you’re downloading is coming from a reliable, vetted source, contains only the code intended, and is safe to operate? Coming back to software supply chains, the practices surrounding their security and verification of authenticity should be addressed by policy, to affirm the importance and reasoning for doing so, and procedure, so that, by intent, it describes what needs to be done to assure both. The best practices for TPRM (Third Party Risk Management), discussed at length in preceding blog posts, would serve companies well to extend and apply to their software supply chains. If not, this is one more good reason to implement a comprehensive TPRM process, either as a supplement to your GRC tools, or as a first step on the path to their integration into your risk management program. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.