Skip to Content
Software Supply Chain Security
book

Software Supply Chain Security

by Cassie Crossley
February 2024
Intermediate to advanced
244 pages
7h 3m
English
O'Reilly Media, Inc.
Audio summary available
Content preview from Software Supply Chain Security

Chapter 11. People in the Software Supply Chain

There is a saying that security is only as good as its weakest link, and as demonstrated in real-life security breaches, in case after case dating back to the earliest hackers, humans are consistently the weakest link. We are the ones making decisions on how the systems are designed, we select or write the code, and we bring it all together to release it to our customers. Until all code and systems are free of vulnerabilities—which will never happen—we must expect imperfection but strive to improve ourselves in the journey to create more secure applications and products.

Throughout the book, there have been many areas where a person’s role in software supply chain security is a factor. Different frameworks such as NIST SSDF, ISA/IEC 62443-4-1 SDL, and NERC CIP provide requirements and controls to lower the risk of compromise. These requirements include training, governance, management, policies, and procedures. Your organization should continuously perform the practices and controls in this chapter—not only once a year or when a new person joins the organization.

According to a 2022 study by ThriveDX, we have seen cybersecurity awareness grow to 97% in companies, but general awareness training is just the start.1 One way to encourage engagement and adoption of cybersecurity practices is through mandatory cybersecurity training, security champions programs, and internal certifications, as described in this chapter, or external certifications, ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Secure Software Systems

Secure Software Systems

Erik Fretheim, Marie Deschene

Publisher Resources

ISBN: 9781098133696Errata Page