Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security
ID: 178a4c1f-b7f8-5666-a325-ee45103e5a02
STIX ID: report--178a4c1f-b7f8-5666-a325-ee45103e5a02
Feed Name: Security Ledger
This transcript of Security Ledger podcast episode 216 features an interview with Brian Trzupek (DigiCert) about securing the software supply chain. Topics include the role and correct implementation of digital code signing, shifting DevOps and tooling to improve identity and deployment controls, quorum-based deployment approvals, managing signing keys and audit trails, and producing software bills of materials; SolarWinds is cited as a cautionary example of a signed build compromised in the supply chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
