Ctrl Alt Defend

Ctrl Alt Defend Trailer Bonus Episode 2 Season 1

Securing the Software Supply Chain: Recommended Practices for Developers

Securing the Software Supply Chain: Recommended Practices for DevelopersSecuring the Software Supply Chain: Recommended Practices for Developers

00:00
This episode offers a guide to securing software supply chains, focusing on recommended practices for developers, suppliers, and customers. with detailed best practices for developers, emphasizing secure coding, build environment hardening, third-party component verification, and vulnerability response. The episode stresses the importance of secure development lifecycle (SDLC) processes, threat modeling, and artifact creation for auditing and verification. We discuss relevant frameworks like NIST SP 800-218 (SSDF) and SLSA, providing a crosswalk between its recommendations and these standards. 

What is Ctrl Alt Defend?

Casual yet insightful conversations on the latest in cybersecurity and weekly updates on vulnerabilities and solutions.