Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Leadership and ManagementLogical SecurityCybersecurity News

4 things CISOs need to know about software supply chain security

By Kim Lewandowski
ciso

Image from Unsplash

October 14, 2022

If there was still any shortage of public awareness about software supply chain security after SolarWinds, Log4j made sure that every last chief information security officer (CISO) is now aware they have a problem.

For many CISOs, the most startling revelation of the Log4j vulnerability was how difficult it was to discover whether and where the popular library was running in their environments.

Today’s software systems — just like physical supply chains — are a web of complicated and brittle dependencies. Developers aren’t writing software from scratch today so much as they are wiring together third party software (typically from open source), and the end results are systems with hundreds, if not thousands, of unknown dependencies. 

Below are some of the critical considerations emerging as the industry tries to unwind this software supply chain security problem and institute new security mechanisms and controls to make software artifacts secure by default.

1: Better metadata for software provenance

One of the clearest needs that CISOs recognize is better metadata on the third party software that’s being brought into their build systems. Open-source code is obviously hugely beneficial and paramount to developer productivity, but before they put their trust into a software package, can developers be confident that the library they introduced hasn't been tampered with? Do they know who wrote the code, the dependencies it is using or when it was last patched? This concept of “provenance,” understanding where exactly code in organizational software originates, is one of the most important building blocks of software supply chain security.

2: Rethinking security for registries and build systems

Attackers finding a popular open source library or dependency and hacking in that way is just one path of the modern software supply chain breach. Another is through the software registries and build systems themselves.

The good news is that in the wake of recent attacks like Log4j, there’s been a huge investment by the most popular language communities to lock down their registries. Many programming languages are now incorporating code-signing into their registries. Teams are also getting smarter about how build systems can get attacked and insert malicious code. Focusing on this stage of software security can help prevent cyberattacks down the software supply chain.

3: Taming the signal/noise ratio

One of the still unsolved major challenges with software supply chain security is how CISOs can manage threat detection signals and actually decipher the real threats from false alarms. There are many open source packages that have had vulnerabilities for years — so who decides what a “critical” vulnerability is?

There have already cases where open source maintainers are in disagreement about what constitutes “critical,” and it’s going to be difficult for security teams to understand what the real signal is, and what they should pay attention to, when there are thousands of open source components in the typical software supply chain and a lot of noise to sift through.

4: Making software secure by default without disrupting developer productivity 

One of the biggest challenges in solving software supply chain security is really a cultural challenge. How can business and security leaders incentivize developers — who have historically been motivated to ship new features and functionality faster — to slow down to pay attention to the integrity of software packages, roots of trust and provenance? The answer is that security leadership can’t slow them down alone. The solution must involve the right amount of automation and best practices that occur by default, so it doesn’t slow down the natural build process.

KEYWORDS: CISO code DevOps open source security software security supply chain cyber security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Kim lewandowski

Kim Lewandowski — Co-Founder and Head of Product at Chainguard — is an engineer turned product manager. She started her career in the security space working for Lawrence Livermore Labs, and most recently worked for Google. She launched a number of cloud enterprise products and co-created software supply chain security’s most popular open source projects, including Tekton, Security Scorecards and SLSA. Lewandowski also helped create and sat on the initial boards of the Continuous Delivery Foundation and Open Source Security Foundation.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Trophy and soccer ball

Security Experts Discuss Threats to FIFA World Cup 2026

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

Colorful laptop

Organizations Think They Know Who’s Visiting Their Sites. They Don’t.

Construction

Texas Tech University Constructing Critical Infrastructure Security Site

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • cloud graphic with upload arrow in center

    What CISOs need to know about CNAPP

    See More
  • supply-chain-1170x658freepik.jpg

    4 ways to improve software supply chain security

    See More
  • network security

    Fourth-party risk management is essential for software supply chain security

    See More

Related Products

See More Products
  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing