Industry group tackles software supply chain attacks

 

Stop malicious code being inserted during development.

Not-for-profit organisation the Software Assurance Forum for Excellence in Code (SafeCode) today announced a new industry-led resource designed to help suppliers prevent software being deliberately compromised during sourcing, development or distribution.

The Software Supply Chain Integrity Framework (PDF) was jointly developed by SafeCode members, including SAP, EMC, Symantec, Microsoft, Nokia and Juniper Networks.

SafeCode said that the framework is designed to address so-called supply chain attacks, in which malicious code is intentionally inserted into software during its development or maintenance.

Secure code development is only one element of software assurance, however, and the software creation and delivery processes must also include integrity controls to enable vendors to deliver uncompromised products, according to SafeCode.

"While SafeCode members have individually implemented software integrity practices, this is the first time that the industry has come together to establish a common framework for ensuring the integrity of software through the global supply chain," said Paul Kurtz, executive director of SafeCode.

"This framework will serve as the foundation for subsequent work aimed at identifying and analysing software integrity best practices, and represents a critical step forward in the industry's efforts to advance software assurance."

Copyright ©v3.co.uk


Industry group tackles software supply chain attacks
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1785

Vote
Do you support the abolition of the Office of the Information Commissioner?