Software Supply Chain Resiliency at Scale
摘要
Software businesses are increasingly dependent on supply chains from several providers to receivers, like traditional business. Real-world software systems of today contain hundreds (perhaps thousands) of smaller programs and modules from various world-wide sources. During a cyberattack, these software supply chains get disrupted. Industry-wide standards that offer guidance to ensure supply chain security and integrity are yet to mature and are still evolving. In this paper, we address the need for a structured, organized approach to compile and automate the decisions related to software supply chain vulnerabilities and pave the way to simultaneous enable organizational knowledge capture and reuse. Specifically, this paper addresses broadly classifying supply chain vulnerabilities to define a scalable solution for software supply chain vulnerabilities, its modeling and evaluation, related metrics, and possible detection and response.