管理软件供应链风险的解决方案 (2021)

ID:64211

大小:5.11 MB

页数:4页

时间:2023-06-29

金币:10

上传者:亚森
The software development lifecycle (SDLC) is not immune to compromise. In fact, it has
emerged as a favored attack vector, acting as the perfect Trojan into your organization and
your customers as it is inherently trusted, has access, and is not inspected by other
security controls.
As a digital business, you are both developing and deploying software to optimize your
business processes. Whether sourced from commercial Trusted Publishers, Open-Source
Software (OSS), or through Internal engineering efforts, this software supply chain isn’t
always vetted to the level it should be. This ecosystem of third-party software suppliers is
not accountable for the risk they could pose to your business, you are.
SOLUTION BRIEF
Challenges
The compromise of SolarWinds’ Orion software is the latest example of how advanced
attackers can successfully circumvent traditional security controls, and in this case place
backdoor software into unsuspecting organizations through an otherwise trusted channel.
Unfortunately, existing security solutions are limited to the discovery of vulnerabilities,
open source licensing violations, or coding defects. They are not addressing the actual
malware that may be unsuspectedly built into the code, maliciously injected into the code,
or abused certificates intent on exploiting trust. When this software is placed into
production, malware has successfully infiltrated the organization. And these cyber risks
can lead to operational downtime, productivity loss, data loss, and reduced trust.
ReversingLabs Solutions
for Managing your Software
Supply Chain Risks
BRINGING TRUST TO YOUR DIGITAL BUSINESS
SOFTWARE
DEVELOPERS
END
USERS
3rd Party Risk
DEVELOP BUILD & TEST RELEASE & PRODUCTION DEPLOY & UPDATE
APPROVED SOFTWARE
EXTERNAL REPOSITORIES OPEN SOURCE
ENGINEERING QA RELEASE MGMT
ReversingLabs
IT-OPS
SOFTWARE PUBLISHERS
RELEASES
PATCHES
Software Development Life Cycle (SDLC)
Software & Patch Management
Build Inspection
1
Release Validation
2
Software Acceptance
3
1
2
3
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭