Tackling Software Supply Chain Security: A Discussion with Cassie Crossley
Software supply challenges are becoming increasingly complex to navigate due to the evolving cyber-threat landscape. In a recent episode of CISO Tradecraft, a podcast dedicated to elevating cybersecurity leadership, host G Mark Hardy discusses the pressing issues of software supply chain security with subject-matter expert, Cassie Crossley.
**Understanding Software Supply Chain Security**
Crossley, author of the pioneering book "Navigating Software Supply Chain Security," engages in a comprehensive discussion about the intricacies of software security. Throughout the conversation, Hardy and Crossley emphasized the criticality of judiciously vetting vendors, adequately securing supply chains, and the role of a secure development life cycle (SDLC) in system integrity.
The critical aspect of this conversation begins with recognizing the inherent vulnerabilities of relying solely on big-name suppliers. Crossley illustrates this with an example of a product containing approximately only 35 direct suppliers. Yet, given dependencies on open source and commercial libraries, chip manufacturers, and the like, this expands into nearly 498 dependencies and upstream suppliers.
**Implementing Security Measures in Software Development**
To address this complicated web of dependencies, companies must be diligent about their security posture, particularly in the SDLC. Crossley shares her insights on this topic, illustrating how security should be integrated into the DNA of each development team. This requires regular threat modeling and level-appropriate security reviews, including secure coding rules.
Crossley extends this argument to even efficient practices like low-code/no-code platforms. While these may be suitable to expedite processes, these tools often lack necessary security consideration and entail a significant risk for data protection and access control issues.
**Software Bill of Materials (SBOM): A Solution?**
The conversation segues into the advent of Software Bill of Materials (SBOMs) mandated by the White House. The duo acknowledges that SBOMs could be an effective tool in supply chain security. Still, they insist that its effectiveness depends on how accurately it features proprietary code, and commercial dependencies or transitive dependencies.
Despite their potential, SBOMs are not the complete solution for validation and validation of product integrity. Crossley emphasizes the confluence of other promise methods like hash controls, signed products, trusted platforms modules, and more.
Above all, both Hardy and Crossley emphasize that, given the rapidly evolving cyber threat landscape, companies and CISOs must remain vigilant and adaptable.
**Summary**
Crossley's insights offer an enlightening look into the intricacies of software supply chain security. As the threat landscape continues to evolve, it's increasingly vital for companies and cybersecurity leaders to understand their dependencies thoroughly and navigate the challenges of supply chain security.
Boundaries between operations and cybersecurity are dissolving, and the onus rests upon companies to build robust, secure systems. By incorporating cybersecurity measures early in the development process and continuously monitoring for emerging vulnerabilities, industries can preserve the integrity of their supply chains while ensuring their systems' security.
To learn more be sure to listen to the full interview:



