Software Supply Chain Risks ⎪Cassie Crossley (VP Supply Chain Security, Schneider Electric)
ID: fa1d4381-5674-5894-a66a-f5ac4a82eafd
STIX ID: report--fa1d4381-5674-5894-a66a-f5ac4a82eafd
Feed Name: Security Boulevard
An interview-driven article with Cassie Crossley examines the growing threat of software supply chain attacks and shares practical defenses: rigorous review of open source components (with the XZ backdoor as a case study), understanding the limits of SBOMs, securing build and development environments, continuous monitoring, third-party risk governance aligned to NIST CSF 2.0, threat modeling, and developer training; it references SolarWinds and Colonial Pipeline to underscore the stakes and advocates strong governance and vigilance across the lifecycle.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
