Chapter 5. Securing Your Supply Chain
Supply Chain is like nature, it is all around us.
Dave Waters
This it is:
‘Tis better that the enemy seek us.
So shall he waste his means, weary his soldiers,
Doing himself offense, whilst we, lying still,
Are full of rest, defense, and nimbleness.
Cassius, Julius Caesar, Act 4, Scene 3, William Shakespeare
We’ve come a long way. From the embarrassing exchanges with MI5, through the discovery and rapid securing of a shadow cloud, to implementing tight, context-rich security OODA loops around our own code. From our code to our cloud, our CNAPP has become our collective superpower.
If only our code was an island. If only there was just our code packed and running in our cloud. But we know this is not the case. Our code is just the tip of the iceberg: a thin veneer on top of substantial depths.
It’s time to secure those depths. To secure the complex and substantial third-party dependencies on which your code relies.
It’s time to secure your cloud native supply chain.
Introducing Your Cloud Native Supply Chain
“If your supply chain doesn’t worry you, you’re not looking closely enough.”
The fear instantly set in. I’d been used to thinking of our software development lifecycle as a funnel or a stream, but now there was a new metaphor: a supply chain. What did that even mean? Was it orthogonal to what I understood as my pipeline, or was it one and the same?
“Do you even know everything you are running in production?”
Of course I knew, didn’t ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access