Supply Chain Security
Evan discusses the rising threat of compromised CI/CD systems and software supply chain attacks, emphasizing the need for vigilance in build processes. Doug highlights how infrastructure as code has transformed security approaches within zero trust networks, enabling automated and reactive configurations that ensure tighter control over systems. The conversation underscores the importance of automation in maintaining a robust security posture across a larger fleet of systems.In this clip
From this podcast

Software Engineering Radio - the podcast for professional software developers
Episode 385: Evan Gilman and Doug Barth on Zero-Trust Networks
Related Questions
Can open source have tighter control in the context of this episode Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain and this clip Code Audit Challenges?
Can open source have tighter control in the context of the episode Reproducible builds and secure software and the clip Preventing SDK Vulnerabilities from Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain, and the clip Code Audit Challenges?
Is code security a growing concern based on the episode The DevOps Handbook – Anticipating Problems and the clip Security Insights, as well as the episode Big breaches (and how to avoid them) and the clip Bridging the InfoSec Gap?