CISO Tradecraft®

#171 - Navigating Software Supply Chain Security (with Cassie Crossley)


Listen Later

In this episode of CISO Tradecraft, host G Mark Hardy converses with Cassie Crossley, author of the book on software supply chain security. Hardy explores the importance of cybersecurity, the structure of software supply chains, and the potential risks they pose. Crossley shares her expert insights on different software source codes and the intricacies of secure development life cycle. She highlights the significance of Software Bill of Materials (SBOM) and the challenges in maintaining the integrity of software products. The discussion also covers the concept of counterfeits in the software world, stressing the need for continuous monitoring and a holistic approach towards cybersecurity.

Link to the Book: https://www.amazon.com/Software-Supply-Chain-Security-End/dp/1098133706?&_encoding=UTF8&tag=-0-0-20&linkCode=ur2

Transcripts: https://docs.google.com/document/d/1SJS2VzyMS-xLF0vlGIgrnn5cOP8feCV9

Chapters

  • 00:00 Introduction
  • 01:44 Discussion on Software Supply Chain Security
  • 02:33 Insights into Secure Development Life Cycle
  • 03:20 Understanding the Importance of Supplier Landscape
  • 05:09 The Role of Security in Software Supply Chain
  • 07:29 The Impact of Vulnerabilities in Software Supply Chain
  • 09:06 The Importance of Secure Software Development Life Cycle
  • 14:13 The Role of Frameworks and Standards in Software Supply Chain Security
  • 17:39 Understanding the Importance of Business Continuity Plan
  • 20:53 The Importance of Security in Agile Development
  • 24:01 Understanding OWASP and Secure Coding
  • 24:20 The Importance of API Security
  • 24:50 The Concept of Shift Left in Software Development
  • 25:20 The Role of Culture in Software Development
  • 25:52 Exploring Different Source Code Types
  • 26:19 The Rise of Low Code, No Code Platforms
  • 28:53 The Potential Risks of Generative AI Source Code
  • 34:24 Understanding Software Bill of Materials (SBOM)
  • 41:07 The Challenge of Spotting Counterfeit Software
  • 41:36 The Importance of Integrity Checks in Software Development
  • 45:45 Closing Thoughts and the Importance of Cybersecurity Awareness
  • ...more
    View all episodesView all episodes
    Download on the App Store

    CISO Tradecraft®By G Mark Hardy & Ross Young

    • 4.8
    • 4.8
    • 4.8
    • 4.8
    • 4.8

    4.8

    48 ratings


    More shows like CISO Tradecraft®

    View all
    Risky Business by Patrick Gray

    Risky Business

    369 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    639 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    370 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,017 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    320 Listeners

    Click Here by Recorded Future News

    Click Here

    414 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    7,953 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    175 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    188 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    315 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    73 Listeners

    Life of a CISO with Dr. Eric Cole by Dr. Eric Cole

    Life of a CISO with Dr. Eric Cole

    33 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    134 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    43 Listeners

    The AI Fix by Graham Cluley and Mark Stockley

    The AI Fix

    33 Listeners