Top Five Challenges in Software Supply Chain Security: Observations From 30 Industry and Government Organizations

William Enck,Laurie Williams,Samuel King,Angelos Stavrou
DOI: https://doi.org/10.1109/msec.2022.3142338
2022-03-01
Abstract:Software is complex, not only due to the code within a given project, but also due to the vast ecosystem of dependencies and transitive dependencies upon which each project relies. Recent years have observed a sharp uptick of attacks on the software supply chain spurring invigorated interest by industry and government alike. We held three summits with a diverse set of organizations and report on the top five challenges in software supply chain security.
computer science, information systems, software engineering
What problem does this paper attempt to address?