This description was written by a machine and published without a person checking it. It is what the agent made of this grouping, and not a statement anybody has stood behind.

The code you did not write

A subject the papers are about. The loosest grouping, and the one to reach for last.

The software supply chain after SolarWinds and Log4j. Collects the attack surveys, the guidance on judging dependencies, and the instruments that make such guidance binding. Membership requires the work to treat code you did not write as the exposure.

3 references

Securing the Software Supply Chain: Recommended Practices for Managing Open-Source Software and Software Bill of Materials
Enduring Security Framework Software Supply Chain Working Panel (2023) · National Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence · National Security Agency, Cybersecurity and Infrastructure Security Agency, and Office of the Director of National Intelligence
Update to Memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices
Office of Management and Budget (2023) · Executive Office of the President · Executive Office of the President
Software supply chain attacks, a threat to global cybersecurity: SolarWinds' case study
Jeferson Martínez and others (2021) · International Journal of Safety and Security Engineering