Software Engineering Institute (SEI) Podcast Series

Incorporating Supply-Chain Risk and DevSecOps into a Cybersecurity Strategy


Listen Later

Organizations are turning to DevSecOps to produce code faster and at lower cost, but the reality is that much of the code is actually coming from the software supply chain through code libraries, open source, and third-party components where reuse is rampant. The downside is that this reused code contains defects unknown to the new user, which, in turn, propagate vulnerabilities into new systems. This is troubling news in an operational climate already rife with cybersecurity risk. Organizations must develop a cybersecurity engineering strategy for systems that addresses the integration of DevSecOps with the software supply chain. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Carol Woody, a principal researcher in the SEI’s CERT Division, talks with Suzanne Miller about supply-chain issues and the planning needed to integrate software from the supply chain into operational environments. The discussion includes building a cybersecurity engineering strategy for DevSecOps that addresses those supply-chain challenges.

...more
View all episodesView all episodes
Download on the App Store

Software Engineering Institute (SEI) Podcast SeriesBy Members of Technical Staff at the Software Engineering Institute

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

18 ratings


More shows like Software Engineering Institute (SEI) Podcast Series

View all
Global News Podcast by BBC World Service

Global News Podcast

7,803 Listeners

Dan Carlin's Hardcore History by Dan Carlin

Dan Carlin's Hardcore History

63,312 Listeners

Make It Real by CMU Engineering

Make It Real

0 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

628 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,009 Listeners

Pod Save America by Crooked Media

Pod Save America

86,216 Listeners

Hacking Humans by N2K Networks

Hacking Humans

312 Listeners

Post Reports by The Washington Post

Post Reports

5,442 Listeners

SEI Cyber Talks by Members of Technical Staff

SEI Cyber Talks

0 Listeners

Rustacean Station by Rustacean Station

Rustacean Station

62 Listeners