Software supply chain: Difference between revisions

Content deleted Content added
there are numerous reliable sources already listed in the article, and it's an ongoing subject of concern for NTIA, DOD, FDA, Underwrites Lab, etc. I'll try to add some of that newer material as well. The assertion that it was SEO material is incorrect.
updated info about the legislation
Line 7:
Understanding the supply chain of software, obtaining a software BOM, and using it to analyze known vulnerabilities are crucial in [[Risk management|managing risk]].<ref>{{cite web |url=http://docs.ismgcorp.com/files/external/WP_FSISAC_Third_Party_Software_Security_Working_Group.pdf |format=PDF |title=Appropriate Software Security Control Types for Third Party Service and Product Providers |publisher=Docs.ismgcorp.com |access-date=2015-06-12}}</ref><ref>{{cite web |url=https://www.owasp.org/index.php/Top_10_2013-A9-Using_Components_with_Known_Vulnerabilities |title=Top 10 2013-A9-Using Components with Known Vulnerabilities |access-date=2015-06-12}}</ref><ref>{{cite web |url=https://www.cert.gov.uk/wp-content/uploads/2015/02/Cyber-security-risks-in-the-supply-chain.pdf |format=PDF |title=Cyber-security risks in the supply chain |publisher=Cert.gov.uk |access-date=2015-06-12}}</ref>
 
The Cyber Supply Chain Management and Transparency Act of 2014<ref>{{cite web |url=https://www.congress.gov/bill/113th-congress/house-bill/5793|title=H.R.5793 - 113th Congress (2013-2014): Cyber Supply Chain Management and Transparency Act of 2014 - Congress.gov - Library of Congress |access-date=2015-06-12}}</ref> is pending{{When|date=March 2018}}was US legislationslegislation that requiresproposed to require government agencies to obtain software BOMs for any new products they purchase. It also requireswould have required obtaining software BOMs for "any software, firmware, or product in use by the United States Government". Thought it ultimately didn't pass, this act did bring awareness to government and spurred later legislation such as "Internet of Things Cybersecurity Improvement Act of 2017."<ref>{{cite web | url=https://www.warner.senate.gov/public/_cache/files/8/6/861d66b8-93bf-4c93-84d0-6bea67235047/8061BCEEBF4300EC702B4E894247D0E0.iot-cybesecurity-improvement-act---fact-sheet.pdf | title=Internet of Things Cybersecurity Improvement Act of 2017 | access-date=2020-02-26}}</ref><ref>{{cite web| url=https://devops.com/cybersecurity-improvement-act-2017-ghost-congress-past/ | title=Cybersecurity Improvement Act of 2017: The Ghost of Congress Past | access-date=2020-02-26}}</ref>
 
==References==