Skip to content

Opening book details…

Can I read S3C2 Summit 2202-09: Industry Secure Suppy Chain Summit on EtoBox?

S3C2 Summit 2202-09: Industry Secure Suppy Chain Summit by Tran, Mindy; Acar, Yasemin; Cucker, Michel; Enck, William; Kapravelos, Alexandros; Kastner, Christian; Williams, Laurie is a scholarly article available to read on EtoBox.

What is S3C2 Summit 2202-09: Industry Secure Suppy Chain Summit about?

Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing fatal damage to businesses and organizations. Past well-known examples of software supply chain attacks are the SolarWinds or log4j incidents that have affected thousands of customers and businesses. The US government and industry are equally interested in enhancing software supply chain security. We conducted six panel discussions with a diverse set of 19 practitioners from industry. We asked them open-ended questions regarding SBOMs, vulnerable dependencies, malicious commits, build and deploy, the Executive Order, and standards compliance. The goal of this summit was to enable open discussions, mutual sharing, and shedding light on common challenges that industry practitioners with practical experience face when securing their software supply chain. This paper summarizes the summit held on September 30, 2022.

Author
Tran, Mindy; Acar, Yasemin; Cucker, Michel; Enck, William; Kapravelos, Alexandros; Kastner, Christian; Williams, Laurie
Published
2023
Language
EN

More by Tran, Mindy; Acar, Yasemin; Cucker, Michel; Enck, William; Kapravelos, Alexandros; Kastner, Christian; Williams, Laurie

Browse all works by Tran, Mindy; Acar, Yasemin; Cucker, Michel; Enck, William; Kapravelos, Alexandros; Kastner, Christian; Williams, Laurie