Evaluating and Mitigating Software Supply Chain Security Risks

SEI Report
In this 2010 report, the authors identify software supply chain security risks and specify evidence to gather to determine if these risks have been mitigated.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2010-TN-016
DOI (Digital Object Identifier)
10.1184/R1/6573497.v1

Abstract

The Department of Defense (DoD) is concerned that security vulnerabilities could be inserted into software that has been developed outside of the DoD’s supervision or control. This report presents an initial analysis of how to evaluate and mitigate the risk that such unauthorized insertions have been made. The analysis is structured in terms of actions that should be taken in each phase of the DoD acquisition life cycle.

Cite This SEI Report

Ellison, R., Goodenough, J., Weinstock, C., & Woody, D. (2010, May 1). Evaluating and Mitigating Software Supply Chain Security Risks. (SEI Report CMU/SEI-2010-TN-016). Retrieved September 16, 2026, from https://doi.org/10.1184/R1/6573497.v1.

@techreport{ellison_2010,
author={Ellison, Robert and Goodenough, John and Weinstock, Charles and Woody, Dr. Carol},
title={Evaluating and Mitigating Software Supply Chain Security Risks},
month={May},
year={2010},
number={{CMU/SEI-2010-TN-016},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/6573497.v1},
url={https://doi.org/10.1184/R1/6573497.v1},
note={Accessed: 2026-Sep-16}
}

Ellison, Robert, John Goodenough, Charles Weinstock, and Dr. Carol Woody. "Evaluating and Mitigating Software Supply Chain Security Risks." (CMU/SEI-2010-TN-016). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, May 1, 2010. https://doi.org/10.1184/R1/6573497.v1.

R. Ellison, J. Goodenough, C. Weinstock, and D. Woody, "Evaluating and Mitigating Software Supply Chain Security Risks," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-2010-TN-016, 1-May-2010 [Online]. Available: https://doi.org/10.1184/R1/6573497.v1. [Accessed: 16-Sep-2026].

Ellison, Robert, John Goodenough, Charles Weinstock, and Dr. Carol Woody. "Evaluating and Mitigating Software Supply Chain Security Risks." (SEI Report CMU/SEI-2010-TN-016). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 May. 2010. https://doi.org/10.1184/R1/6573497.v1. Accessed 16 Sep. 2026.

Ellison, Robert; Goodenough, John; Weinstock, Charles; & Woody, Dr. Carol. Evaluating and Mitigating Software Supply Chain Security Risks. CMU/SEI-2010-TN-016. Software Engineering Institute. 2010. DOI: 10.1184/R1/6573497.v1. https://doi.org/10.1184/R1/6573497.v1