arXiv Open Access 2022

What is Software Supply Chain Security?

Marcela S. Melara Mic Bowman
Lihat Sumber

Abstrak

The software supply chain involves a multitude of tools and processes that enable software developers to write, build, and ship applications. Recently, security compromises of tools or processes has led to a surge in proposals to address these issues. However, these proposals commonly overemphasize specific solutions or conflate goals, resulting in unexpected consequences, or unclear positioning and usage. In this paper, we make the case that developing practical solutions is not possible until the community has a holistic view of the security problem; this view must include both the technical and procedural aspects. To this end, we examine three use cases to identify common security goals, and present a goal-oriented taxonomy of existing solutions demonstrating a holistic overview of software supply chain security.

Topik & Kata Kunci

Penulis (2)

M

Marcela S. Melara

M

Mic Bowman

Format Sitasi

Melara, M.S., Bowman, M. (2022). What is Software Supply Chain Security?. https://arxiv.org/abs/2209.04006

Akses Cepat

Lihat di Sumber
Informasi Jurnal
Tahun Terbit
2022
Bahasa
en
Sumber Database
arXiv
Akses
Open Access ✓