SE Radio 606: Charlie Jones on Third-Party Software Supply Chain Risks

Topics covered
Popular Clips
Episode Highlights
Continuous Eval
Continuous evaluation of third-party software is crucial due to the dynamic nature of software development. emphasizes that a single evaluation is insufficient, as software constantly evolves, altering the risk profile with each update 1. He suggests a structured approach to managing supplier risks by identifying critical suppliers, ranking them by risk, and applying consistent testing methodologies 2. This ensures that any vulnerabilities, like malware, are identified and mitigated before deployment.
Software vendor relationships are very different than that of a traditional enterprise relationship... It's the same from onboarding to offboarding, software is very dynamic.
---
Regular reassessment helps maintain security and integrity throughout the software lifecycle.
Binary Analysis
Binary analysis emerges as a powerful tool for evaluating third-party software independently of vendor disclosures. explains that this method allows enterprises to analyze risks by examining the binary itself, bypassing the need for source code access 3. This approach, combined with automation, helps manage the complexity of modern software packages, which can contain thousands of components 4.
Binary analysis... allows you to not only generate an S BOM, but also analyze the risk presented by all those components and dependencies within the s Bom, just using the binary itself.
---
By layering binary analysis with other technologies like AI, organizations can better understand and mitigate potential threats.
Related Episodes


SE Radio 559: Ross Anderson on Software Obsolescence
Answers 383 questions

Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain
Answers 383 questions

Episode 535: Dan Lorenc on Supply Chain Attacks
Answers 383 questions

SE Radio 642: Simon Wijckmans on Third-Party Browser Script Security
Answers 383 questions

SE Radio 584: Charles Weir on Ruthless Security for Busy Developers
Answers 383 questions

SE Radio 630: Luis Rodríguez on the SSH Backdoor Attack
Answers 383 questions

SE-Radio Episode 314: Scott Piper on Cloud Security
Answers 383 questions

SE-Radio Episode 288: DevSecOps
Answers 383 questions

SE-Radio-Episode-273-Steve-McConnell-on-Software-Estimation
Answers 383 questions

SE-Radio Episode 242: Dave Thomas on Innovating Legacy Systems
Answers 383 questions

SE Radio 637: Steve Smith on Software Quality
Answers 383 questions

SE-Radio Episode 262: Software Quality with Bill Curtis
Answers 383 questions

SE Radio 574: Chad Michel on Software as an Engineering Discipline
Answers 383 questions

SE Radio 635: Stevie Caldwell on Zero-Trust Architecture
Answers 383 questions

Episode 112: Roles in Software Engineering II
Answers 383 questions














