A Systemic Approach for Assessing Software Supply-Chain Risk
• SEI Report
Publisher
Software Engineering Institute
Abstract
In today’s business environment, multiple organizations must routinely work together in software supply chains when acquiring, developing, operating, and maintaining software products. The programmatic and product complexity inherent in software supply chains increases the risk that defects, vulnerabilities, and malicious code will be inserted into a delivered software product. As a result, effective risk management is essential for establishing and maintaining software supply-chain assurance over time. The Software Engineering Institute (SEI) is developing a systemic approach for assessing and managing software supply-chain risks. This paper highlights the basic approach being implemented by SEI researchers and provides a summary of the status of this work.
Part of a Collection
Cybersecurity Engineering Research: Supply Chain and Commercial-Off-the-Shelf (COTS) Assurance Collection
Cite This SEI Report
Dorofee, A., Woody, D., Alberts, C., Creel, R., & Ellison, R. (2013, May 14). A Systemic Approach for Assessing Software Supply-Chain Risk. Retrieved September 12, 2026, from https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/.
@techreport{dorofee_2013,
author={Dorofee, Audrey and Woody, Dr. Carol and Alberts, Christopher and Creel, Rita and Ellison, Robert},
title={A Systemic Approach for Assessing Software Supply-Chain Risk},
month={May},
year={2013},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/},
note={Accessed: 2026-Sep-12}
}
Dorofee, Audrey, Dr. Carol Woody, Christopher Alberts, Rita Creel, and Robert Ellison. "A Systemic Approach for Assessing Software Supply-Chain Risk." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, May 14, 2013. https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/.
A. Dorofee, D. Woody, C. Alberts, R. Creel, and R. Ellison, "A Systemic Approach for Assessing Software Supply-Chain Risk," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 14-May-2013 [Online]. Available: https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/. [Accessed: 12-Sep-2026].
Dorofee, Audrey, Dr. Carol Woody, Christopher Alberts, Rita Creel, and Robert Ellison. "A Systemic Approach for Assessing Software Supply-Chain Risk." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 14 May. 2013. https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/. Accessed 12 Sep. 2026.
Dorofee, Audrey; Woody, Dr. Carol; Alberts, Christopher; Creel, Rita; & Ellison, Robert. A Systemic Approach for Assessing Software Supply-Chain Risk. Software Engineering Institute. 2013. https://www.sei.cmu.edu/library/a-systemic-approach-for-assessing-software-supply-chain-risk/