Evaluating and Mitigating Software Supply Chain Security Risks

The Department of Defense (DoD) is concerned that security vulnerabilities could be inserted into software that has been developed outside of the DoD's supervision or control. This report presents an initial analysis of how to evaluate and mitigate the risk that such unauthorized insertions have been made. The analysis is structured in terms of actions that should be taken in each phase of the DoD acquisition life cycle.

PDF [1135 KB]

Authors

Robert J. Ellison

John B. Goodenough

Charles B. Weinstock

Carol Woody

This report is related to the following area(s) of work:

Software Assurance

Technical Note
CMU/SEI-2010-TN-016
May 2010

Cite This Report

SEI:

Ellison, Robert; Goodenough, John; Weinstock, Charles; & Woody, Carol. Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Software Engineering Institute, Carnegie Mellon University, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm

IEEE:

R. Ellison, J. Goodenough, C. Weinstock, and C. Woody, "Evaluating and Mitigating Software Supply Chain Security Risks," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Note CMU/SEI-2010-TN-016, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm

APA:

Ellison, R., Goodenough, J., Weinstock, C., & Woody, C. (2010). Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Retrieved May 23, 2013, from the Software Engineering Institute, Carnegie Mellon University website: http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm

CHI:

Ellison, Robert, John Goodenough, Charles Weinstock, and Carol Woody. Evaluating and Mitigating Software Supply Chain Security Risks (CMU/SEI-2010-TN-016). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2010. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm

MLA:

Ellison, R., Goodenough, J., Weinstock, C., & Woody, C. 2010. Evaluating and Mitigating Software Supply Chain Security Risks (Technical Report CMU/SEI-2010-TN-016). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://www.sei.cmu.edu/library/abstracts/reports/10tn016.cfm

Find Us Here

Find us on Youtube  Find us on LinkedIn  Find us on twitter  Find us on Facebook

Share This Page

Share on Facebook  Send to your Twitter page  Save to del.ico.us  Save to LinkedIn  Digg this  Stumble this page.  Add to Technorati favorites  Save this page on your Google Home Page 

For more information

Contact Us

info@sei.cmu.edu

412-268-5800

Help us improve

Visitor feedback helps us continually improve our site.

Please tell us what you
think with this short
(< 5 minute) survey.