Share E-Book
Scan to open this page

Scan with your phone to open this page

AuthorCassie Crossley

Trillions of lines of code help us in our lives, companies, and organizations. But just a single software cybersecurity vulnerability can stop entire companies from doing business and cause billions of dollars in revenue loss and business recovery. Securing the creation and deployment of software, also known as software supply chain security, goes well beyond the software development process. This practical book gives you a comprehensive look at security risks and identifies the practical controls you need to incorporate into your end-to-end software supply chain. Author Cassie Crossley demonstrates how and why everyone involved in the supply chain needs to participate if your organization is to improve the security posture of its software, firmware, and hardware. With this book, you'll learn how to: Pinpoint the cybersecurity risks in each part of your organization's software supply chain Identify the roles that participate in the supply chain—including IT, development, operations, manufacturing, and procurement Design initiatives and controls for each part of the supply chain using existing frameworks and references Implement secure development lifecycle, source code security, software build management, and software transparency practices Evaluate third-party risk in your supply chain

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Software Supply Chain Security: Securing the End-to-end Supply Chain for Software, Firmware, and Hardware ## 【One-Line Pitch】 A comprehensive, practitioner-focused guide to identifying and mitigating cybersecurity risks across the entire software supply chain—from code repositories and build systems to manufacturing and distribution—essential reading for security professionals, developers, and procurement teams who need practical controls, not just theory. ## 【Book Arc】 - **Opening (~0%–9%)**: Defines software supply chain security, its scope beyond development, and why it matters—using real-world examples like SolarWinds and Log4Shell to illustrate the stakes. Introduces key terminology and the full range of participants (IT, development, operations, manufacturing, procurement). - **Early (~9%–28%)**: Surveys the global regulatory landscape—EU NIS2, Australian Cyber Security Centre guidance, US NIST frameworks, and others—establishing why compliance and risk management are now mandatory considerations for any organization. - **Early (~28%–38%)**: Dives into risk management foundations and supply chain frameworks, including NIST SP 800-161 (C-SCRM), COBIT 2019, and the UK Supplier Assurance Framework, showing how to structure a formal supply chain risk program. - **Middle (~38%–47%)**: Transitions from frameworks to practice, covering infrastructure security across the product lifecycle—developer environments, code repositories, build platforms, testing labs, production systems, and distribution channels—emphasizing the CIA triad in every environment. - **Middle (~47%–end)**: Moves into the secure development lifecycle (SDL), source code management, build integrity, and deployment controls, with attention to IoT, OT, and embedded systems where traditional security approaches fall short. ## 【Key Takeaways】 - **Software supply chain security extends far beyond development** (Opening): The chain includes hardware, firmware, third-party libraries, manufacturing, distribution, and even customer staging—every handoff is an attack surface. Organizations must map their full chain before implementing controls. - **Regulatory pressure is global and growing** (Early): From EU NIS2 to Australian and US frameworks, governments now mandate supply chain security practices. Compliance is no longer optional for suppliers to critical sectors—it's a market access requirement. - **Risk management is the foundation** (Early): Before selecting any framework, organizations need a working risk management process. NIST SP 800-161's C-SCRM framework provides 12 dimensions—from culture and awareness to integrity and maintainability—that structure a comprehensive program. - **Frameworks are starting points, not endpoints** (Middle): Free resources like NIST and MITRE frameworks offer practical baselines; purchased standards like ISO/IEC 20243 and SCS 9001 enable formal certification. Start with the free controls, then mature into formal standards if your market demands it. - **Infrastructure security must cover the entire lifecycle** (Middle): Many organizations secure business environments but neglect development, testing, and supply chain environments. The CIA triad (confidentiality, integrity, availability) must apply everywhere—including developer laptops and manufacturing systems. - **Real-world attacks exploit development environments** (Middle): The 3CX breach via X_TRADER software in a development environment shows how attackers target the least-protected parts of the chain. Code theft and tampering are realistic threats that require monitoring and controls. - **Third-party risk is inherent and must be managed** (Early): External suppliers, open source libraries, and commercial components all introduce risk. Organizations need structured processes to evaluate and continuously monitor these dependencies. ## 【Reading Tips】 - **Skim Chapter 1's regulatory survey** (~9%–28%) if you're not in a regulated industry—the key takeaway is that global requirements exist and are converging; you can return to specifics when needed. - **Deep-read the NIST SP 800-161 coverage** (~34%–38%): The 12 C-SCRM dimensions and the appendix templates (strategy, policy, plan, risk assessment) are directly actionable. The book even suggests using risk scenarios as tabletop exercises. - **Pay special attention to Chapter 3's infrastructure coverage** (~47%+): This is where the book gets most practical, walking through each environment type (developer, build, test, production, manufacturing) with specific controls. This is the chapter to reference when auditing your own environments. - **Use the book as a reference, not a one-sitting read**: The structure supports jumping to relevant chapters—frameworks in Chapter 2, infrastructure in Chapter 3, SDL in Chapter 4, source/build management in Chapter 5. Mark sections relevant to your role and revisit as needed. - **For IoT/OT/embedded practitioners**: The SDL chapter includes specific considerations for these systems, which differ meaningfully from traditional IT software—don't skip this section even if you're experienced with standard SDLC practices. ## 【Coverage Limits】 This guide is based on excerpts covering roughly the first half of the book (through ~47%). Later chapters on source code management, build integrity, software transparency (SBOMs), and third-party risk evaluation are referenced in the table of contents but not detailed in the source material. ##
Page 5
k is well organized, making it an effective reference tool. —Leda Muller, Chief Information and Privacy Officer, Stanford University, Residential and Dining...
View in text
Excerpt 2
ve glossary in its Computer Security Resource Center (CSRC).7 Although NIST is a US agency in the Department of Com‐ merce, its mission is to advance measure...
View in text
Excerpt 3
uence in the risk management process. Continual improvement Enhance the risk management process through learning and experience. Figure 2-3. ISO 31000 princi...
View in text
Excerpt 4
ctual property and the final product, including code, data, defect information, scripts, and production files, relies on the various infrastructure, systems,...
View in text
Excerpt 5
et the same attention and oversight in development, lab, or manufacturing environments. These environments and processes present security risks that can be r...
View in text
Excerpt 6
ny number of metrics and apply certain weights (e.g., three times the weight for a product that had an easy vulnerability) to define a measure‐ ment system t...
View in text
Excerpt 7
ges rather than internal packages.21 This vulnerability can lead to injected malware during the build process, as was the case when a security researcher upl...
View in text
Excerpt 8
well as receive mitigations and hardening recommendations. Once everything is fully tested—including penetration tested—the testing process can be automated...
View in text
Tags
AI categories
CybersecurityCloud NativeDevOps
ISBN: 1098133706
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 242
File Format: PDF
File Size: 5.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…