Diamond Member Pelican Press 0 Posted August 29, 2024 Diamond Member Share Posted August 29, 2024 This is the hidden content, please Sign In or Sign Up Study highlights secure software supply chain best practices The latest edition of Suse’s Securing the cloud report has found that almost every IT decision-maker polled is concerned about the security risks associated with their software supply chain. The 2024 edition of the report, based on a survey of 820 IT engineers, architects, developers, security managers and directors, found that 94% of IT decision-makers intend to review their own software supply chain to increase security. Almost half (46%) of the IT decision-makers polled are considering certifying processes and tools used to build software as a key measure to mitigate the risk and impact of supply chain attacks In the report, Suse said the survey data shows that This is the hidden content, please Sign In or Sign Up is considered the most important measure to mitigate risk and impact of supply chain attacks. One in four IT decision-makers believes government-recognised supply chain related security certifications (25%) will become more of a priority for them over the next 12 months. IT decision-makers also believe source-code auditability (14%), build quality (15%), or This is the hidden content, please Sign In or Sign Up (SBOM), quality and security (24%) will be re-evaluated upwards in the next few years to become more of a priority. The report polled IT decision-makers in the US, Germany, ***, France and the Netherlands. Those based in the US and Europe believe goals on source-code auditability (14%) will be re-evaluated, with the lowest share in Germany (11%) and the highest in the Netherlands (19%), followed by France (17%). Similarly, when asked about the re-evaluation of SBOM depth, quality and security, respondents in the US (20%) and Germany (20%) saw eye-to-eye. Europe as a group attributed it a higher likelihood (26%), with the *** (30%) being strongest in agreement. However, Suse noted that the decision to re-evaluate the build quality of their software supply chains ******** a divisive matter. “While last year’s ********* respondents were more likely (40%) to believe this as compared to US respondents (15%), this year, roles were reversed, with more decision-makers from the US (24%) believing it to be the case compared to Europe (12%),” the report’s authors wrote. Suse also found that responses to questions for software supply chain risks were dependent on respondents’ present role in the business. The survey reported that those working as software and network engineers, technical architects, or developers are more likely to believe that goals on source-code auditability will be re-evaluated (24% versus 14% average), but less likely to think goals on SBOM depth, quality and security will be re-evaluated (20% versus 23% average). To mitigate the risk and impact of supply chain attacks, the most popular measures used by the IT decision-makers polled include certifying processes and tools used to build software (46%), leveraging software that is backed by principal software providers (44%) and in-house auditing of software (43%). Certifying processes and tools used to build software is considered more important in the US (59%) compared with Europe (41%). Suse also reported that in-house auditing of software is a significantly more popular measure in Germany (53%) compared with the *** and Netherlands (both 38%), with France at the average (43%). This is the hidden content, please Sign In or Sign Up #Study #highlights #secure #software #supply #chain #practices This is the hidden content, please Sign In or Sign Up This is the hidden content, please Sign In or Sign Up Link to comment https://hopzone.eu/forums/topic/112725-study-highlights-secure-software-supply-chain-best-practices/ Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now