Securing the Software Supply Chain: Recommended Practices for Managing Open-Source Software and Software Bill of Materials

The work

AuthorsEnduring Security Framework Software Supply Chain Working Panel
Editors
Typetechreport
Year2023
Citekeyesf2023securing

Where it appeared

Published inNational Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence
PublisherNational Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence
SeriesESF Recommended Practices Guide

Settled

AbstractNo abstract; the document carries an Executive Summary instead, and this corpus does not treat those as abstracts. It opens 'Cyberattacks target an enterprise's use of cyberspace to disrupt, disable, destroy, or maliciously control a computing environment...' and continues into the SolarWinds and Log4j examples and the Executive Order 14028 background -- framing and motivation rather than a summary of the document's own recommendations. Same decision as on greenarrays2011g144a12, nsa2024fpga and nsa2026asic. Established by reading leaves 1-2.

A copy is held

pdf, 2.1 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via other
Added2026-08-26 00:00 UTC
Approved bya person 2026-08-26 10:15 UTC

Cite it as

@techreport{esf2023securing,
  title        = {Securing the Software Supply Chain: Recommended Practices for Managing Open-Source Software and Software Bill of Materials},
  author       = {Enduring Security Framework Software Supply Chain Working Panel},
  year         = {2023},
  journal      = {National Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence},
  publisher    = {National Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence},
  series       = {ESF Recommended Practices Guide},
}

This record lives at https://refs.drheap.org/esf2023securing/ and will keep doing so.