What SolarWinds Tells Us About Securing the Software Development Supply Chain
ID: a3061074-92e5-5fe7-bc64-32b5b8a18a6c
STIX ID: report--a3061074-92e5-5fe7-bc64-32b5b8a18a6c
Feed Name: Security Ledger
This sponsored article uses the SolarWinds supply-chain breach as a cautionary example to urge organizations to modernize code signing practices. It recommends centralized and automated code-signing management (including code-signing-as-a-service), permission-based access controls, separating signing keys per team, shorter certificate lifetimes and rotation, offline/virtual HSM storage for keys, and integrating signing into CI/CD pipelines to reduce the risk of compromised updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
