Securing Your Software Supply Chain – Practical Approaches to Assess and Improve Software Security

No ratings

Presented at 44CON 2023 by

Software supply chain frameworks like NIST, SLSA, and CIS provide valuable guidelines for securing the software supply chain. However, bridging the gap between theory and practical implementation in auditing and enhancing the security of the software development lifecycle (SDLC) requires further progress. In this session, we will delve into the most critical risks associated with the software development lifecycle and demonstrate how open-source tools can facilitate the assessment and improvement of SDLC security. To bring it to life, we will analyze recent high-profile supply chain breaches executed by attackers and explore effective protective measures. Attendees will walk away with tangible guidance and actionable insights on how to bolster the security of their SDLC. They will leave equipped with practical strategies to implement in their organizations, enabling them to safeguard their software supply chain effectively. Pre-requisites: A laptop with npm install A Github Account