search menu icon-carat-right cmu-wordmark

Software Supply Chain Concerns for DevSecOps Programs

May 2021 Webinar
Aaron K. Reffett, Richard Laughlin

In this webcast, Aaron Reffett and Richard Laughlin explore the important architectural aspects of DevSecOps that are impacted by the software supply chain.

Publisher:

Software Engineering Institute

Watch

Abstract

In a DevSecOps world the software supply chain extends beyond libraries upon which developed software depends. In this webinar we will look at the Solarwinds incident as a worst-case exemplifying the breadth of the software supply chain issues confronting complex DevSecOps programs. We will explore the important architectural aspects of DevSecOps that are impacted by the software supply chain that require attention and potential mitigations to detect and respond to potential incidents.

What attendees will learn:

  • The software supply chain issue is broad and impacts multiple aspects of DevSecOps
  • Programs need to be aware of how the software they leverage presents risks
  • Mitigation strategies must be put in place to address potential issues at the architectural level