Artwork

Content provided by ReversingLabs Inc.. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ReversingLabs Inc. or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Robert Martin of MITRE on Supply Chain System of Trust

25:11
 
Share
 

Manage episode 340664688 series 3393145
Content provided by ReversingLabs Inc.. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ReversingLabs Inc. or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this conversation, Robert Martin of MITRE talks about how the software supply chain is highly complicated, due to an increasing number of things in society becoming cyber-enabled. He and MITRE created the System of Trust (SoT) so that organizations can consider the most important aspects of the software supply chain, giving a more holistic context into the chain’s subsets. The SoT’s goal is to promote transparency, allowing developers to see all of the players in the supply chain.

Martin explained how software is not written neatly end to end, but rather is built with drivers, dependencies, and frameworks that give the supply chain depth and magnitude. If software practitioners are not given visibility into this complicated picture, they will miss the software supply chain risks that pose a threat to their organizations. He stresses that Software Bills of Materials (SBOMs) should be included in this effort, but that practitioners should refer to the SoT in order to best utilize an SBOM, giving them the best chance of mitigating software supply chain risks.

  continue reading

44 episodes

Artwork
iconShare
 
Manage episode 340664688 series 3393145
Content provided by ReversingLabs Inc.. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ReversingLabs Inc. or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this conversation, Robert Martin of MITRE talks about how the software supply chain is highly complicated, due to an increasing number of things in society becoming cyber-enabled. He and MITRE created the System of Trust (SoT) so that organizations can consider the most important aspects of the software supply chain, giving a more holistic context into the chain’s subsets. The SoT’s goal is to promote transparency, allowing developers to see all of the players in the supply chain.

Martin explained how software is not written neatly end to end, but rather is built with drivers, dependencies, and frameworks that give the supply chain depth and magnitude. If software practitioners are not given visibility into this complicated picture, they will miss the software supply chain risks that pose a threat to their organizations. He stresses that Software Bills of Materials (SBOMs) should be included in this effort, but that practitioners should refer to the SoT in order to best utilize an SBOM, giving them the best chance of mitigating software supply chain risks.

  continue reading

44 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play