Underpinning all modern technology - software and hardware - is a supply chain. However, even as “software eats the world,” or we could argue “ate the world,” there is still too little understanding of the software supply chain, with continued focus on hardware. The reality, however, is that software is much easier to pollute than hardware. While there has been an increase in awareness around the need for a coordinated application security strategy, the federal government has historically focused on playing strong defense, putting up walls at the perimeter, and at the end of the digital supply chain.It’s time to shift more security resources further left. In this way, the government can play better offense at the beginning of the digital supply chain so that federal agencies can better protect themselves and the American citizenry.
- Open Source is Powering Federal Software Development - Open source software components are the backbone of federal software supply chains; in fact, 85% to 95% of an application is composed of open source components. Since they are free, and readily available, they allow agencies to save time and money, and in many cases improve quality.
- Agencies Don’t Know How Much Open Source They’re Using - There is a lack of transparency in how much open source software is being used throughout the federal government. A disconnect between the developers and security teams, make it difficult to rectify this, but with proper controls, can be fixed.
NIST Special Publication (SP) 800-161 offers specific supply chain risk management practice recommendations.
- Lack of Open Source Policies Leading to Breaches - According to Sonatype’s DevSecOps Community Survey of 5,500 IT pros, 1 in 4 organizations confirmed or suspected an open source related breach last year. Of organizations with DevOps practices, only 6 in 10 have policies evaluating open source use, and of those not practicing DevOps, it plummets to 2 in 10.
- Cost Emphasized Over Security Protocol - One of the biggest threats comes from the contractors paid to support the federal government and are supposed to be helping protect its sophisticated systems. Too often they are inadvertently introducing vulnerabilities into the supply chain with the emphasis on cost over security.
- Regulations Around Software Development is Coming - In recent years, however, new legislation and recommendations have begun providing a roadmap for where the US should be headed. There is an opportunity for savvy contractors and agencies to get ahead by prioritizing security in their development process now.
“You need to change the system, not just go around the system. You have to make that change last.” Nicolas M. Chaillan, Chief Software Officer, US Air Force - read more in BusinessChief.com