Supply Chain Security
A new type of supply chain attack is emerging, where vulnerabilities in third-party software can compromise a larger network of users. The NIST has introduced the Secure Software Development Framework, which outlines 40 best practice controls to enhance security in software development. Organizations providing software to U.S. government agencies must attest to meeting these standards, ensuring they have plans in place to address any deficiencies.In this clip
From this podcast

Software Engineering Radio - the podcast for professional software developers
SE Radio 606: Charlie Jones on Third-Party Software Supply Chain Risks
Related Questions
Can open source have tighter control in the context of this episode Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain and this clip Code Audit Challenges?
How can open source projects succeed as discussed in the episode Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain and the clip Open Source Security Efforts?