The Department of Defense (DoD) is concerned that security vulnerabilities could be inserted into software that has been developed outside of the DoD's supervision or control. This report presents an initial analysis of how to evaluate and mitigate the risk that such unauthorized insertions have been made. The analysis is structured in terms of actions that should be taken in each phase of the DoD acquisition life cycle.
This report is related to the following area(s) of work:
Software AssuranceTechnical Note
CMU/SEI-2010-TN-016
May 2010
SEI:
Ellison, Robert; Goodenough, John; Weinstock, Charles; & Woody, Carol. Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Software Engineering Institute, Carnegie Mellon University, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm
IEEE:
R. Ellison, J. Goodenough, C. Weinstock, and C. Woody, "Evaluating and Mitigating Software Supply Chain Security Risks," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Note CMU/SEI-2010-TN-016, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm
APA:
Ellison, R., Goodenough, J., Weinstock, C., & Woody, C. (2010). Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Retrieved May 22, 2013, from the Software Engineering Institute, Carnegie Mellon University website: http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm
CHI:
Ellison, Robert, John Goodenough, Charles Weinstock, and Carol Woody. Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm
MLA:
Ellison, R., Goodenough, J., Weinstock, C., & Woody, C. 2010. Evaluating and Mitigating Software Supply Chain Security Risks (Technical Report CMU/SEI-2010-TN-016). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm
For more information