CISO Tradecraft®

#171 - Navigating Software Supply Chain Security (with Cassie Crossley)


Listen Later

In this episode of CISO Tradecraft, host G Mark Hardy converses with Cassie Crossley, author of the book on software supply chain security. Hardy explores the importance of cybersecurity, the structure of software supply chains, and the potential risks they pose. Crossley shares her expert insights on different software source codes and the intricacies of secure development life cycle. She highlights the significance of Software Bill of Materials (SBOM) and the challenges in maintaining the integrity of software products. The discussion also covers the concept of counterfeits in the software world, stressing the need for continuous monitoring and a holistic approach towards cybersecurity.

Link to the Book: https://www.amazon.com/Software-Supply-Chain-Security-End/dp/1098133706?&_encoding=UTF8&tag=-0-0-20&linkCode=ur2

Transcripts: https://docs.google.com/document/d/1SJS2VzyMS-xLF0vlGIgrnn5cOP8feCV9

Chapters

  • 00:00 Introduction
  • 01:44 Discussion on Software Supply Chain Security
  • 02:33 Insights into Secure Development Life Cycle
  • 03:20 Understanding the Importance of Supplier Landscape
  • 05:09 The Role of Security in Software Supply Chain
  • 07:29 The Impact of Vulnerabilities in Software Supply Chain
  • 09:06 The Importance of Secure Software Development Life Cycle
  • 14:13 The Role of Frameworks and Standards in Software Supply Chain Security
  • 17:39 Understanding the Importance of Business Continuity Plan
  • 20:53 The Importance of Security in Agile Development
  • 24:01 Understanding OWASP and Secure Coding
  • 24:20 The Importance of API Security
  • 24:50 The Concept of Shift Left in Software Development
  • 25:20 The Role of Culture in Software Development
  • 25:52 Exploring Different Source Code Types
  • 26:19 The Rise of Low Code, No Code Platforms
  • 28:53 The Potential Risks of Generative AI Source Code
  • 34:24 Understanding Software Bill of Materials (SBOM)
  • 41:07 The Challenge of Spotting Counterfeit Software
  • 41:36 The Importance of Integrity Checks in Software Development
  • 45:45 Closing Thoughts and the Importance of Cybersecurity Awareness
  • ...more
    View all episodesView all episodes
    Download on the App Store

    CISO Tradecraft®By CISO Tradecraft®

    • 4.8
    • 4.8
    • 4.8
    • 4.8
    • 4.8

    4.8

    48 ratings


    More shows like CISO Tradecraft®

    View all
    Risky Business by Patrick Gray

    Risky Business

    362 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    634 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    368 Listeners

    Hacked by Hacked

    Hacked

    176 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,011 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    305 Listeners

    Click Here by Recorded Future News

    Click Here

    386 Listeners

    Malicious Life by Malicious Life

    Malicious Life

    919 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    7,841 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    142 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    182 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    308 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    71 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    117 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners