Strategies for Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines

Ramaswamy Chandramouli · 2023

Software Supply Chain Security August 2023in DevSecOps CI/CD Pipelines Certain commercial equipment, instruments, software, or materials, commercial or non-commercial, are identified in this paper in order to specify the experimental procedure adequately.Such identification does not imply recommendation or endorsement of any product or service by NIST, nor does it imply that the materials or equipment identified are necessarily the best available for the purpose.There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities.The information in this publication, including concepts and methodologies, may be used by federal agencies even before the completion of such companion publications.Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative.For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.Organizations are encouraged to review all draft publications during public comment periods and provide feedback to NIST.Many NIST cybersecurity publications, other than the ones noted above, are available at https://csrc.nist.gov/publications. AuthorityThis publication has been developed by NIST in accordance with its

Read the paper · More papers on PaperTik