Software Engineering Institute (SEI) Podcast Series

Incorporating Supply-Chain Risk and DevSecOps into a Cybersecurity Strategy


Listen Later

Organizations are turning to DevSecOps to produce code faster and at lower cost, but the reality is that much of the code is actually coming from the software supply chain through code libraries, open source, and third-party components where reuse is rampant. The downside is that this reused code contains defects unknown to the new user, which, in turn, propagate vulnerabilities into new systems. This is troubling news in an operational climate already rife with cybersecurity risk. Organizations must develop a cybersecurity engineering strategy for systems that addresses the integration of DevSecOps with the software supply chain. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Carol Woody, a principal researcher in the SEI's CERT Division, talks with Suzanne Miller about supply-chain issues and the planning needed to integrate software from the supply chain into operational environments. The discussion includes building a cybersecurity engineering strategy for DevSecOps that addresses those supply-chain challenges.

...more
View all episodesView all episodes
Download on the App Store

Software Engineering Institute (SEI) Podcast SeriesBy Members of Technical Staff at the Software Engineering Institute

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

18 ratings


More shows like Software Engineering Institute (SEI) Podcast Series

View all
Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,254 Listeners

Software Engineering Radio - the podcast for professional software developers by team@se-radio.net (SE-Radio Team)

Software Engineering Radio - the podcast for professional software developers

272 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,384 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,094 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

623 Listeners

Risky Business by Patrick Gray

Risky Business

373 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

649 Listeners

Thoughtworks Technology Podcast by Thoughtworks

Thoughtworks Technology Podcast

45 Listeners

Smashing Security by Graham Cluley

Smashing Security

319 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,110 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Make It Real by CMU Engineering

Make It Real

0 Listeners

SEI Cyber Talks by Members of Technical Staff

SEI Cyber Talks

0 Listeners

The Journal. by The Wall Street Journal & Spotify Studios

The Journal.

6,118 Listeners

Deep Questions with Cal Newport by Cal Newport

Deep Questions with Cal Newport

1,339 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

16,338 Listeners