
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Author(s): Chris Hughes (Author), Tony Turner (Author), Steve Springett (Editor), Allan Friedman (Foreword)
- Publisher: Wiley
- Publication Date: 8 Jun. 2023
- Edition: 1st
- Language: English
- Print length: 336 pages
- ISBN-10: 1394158483
- ISBN-13: 9781394158485
Book Description
Discover the new cybersecurity landscape of the interconnected software supply chain
In Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, a team of veteran information security professionals delivers an expert treatment of software supply chain security. In the book, you’ll explore real-world examples and guidance on how to defend your own organization against internal and external attacks. It includes coverage of topics including the history of the software transparency movement, software bills of materials, and high assurance attestations.
The authors examine the background of attack vectors that are becoming increasingly vulnerable, like mobile and social networks, retail and banking systems, and infrastructure and defense systems. You’ll also discover:
- Use cases and practical guidance for both software consumers and suppliers
- Discussions of firmware and embedded software, as well as cloud and connected APIs
- Strategies for understanding federal and defense software supply chain initiatives related to security
An essential resource for cybersecurity and application security professionals, Software Transparency will also be of extraordinary benefit to industrial control system, cloud, and mobile security professionals.
Editorial Reviews
Review
“Starting this book off with a proper threat model is precisely what’s needed as a frame for such an important problem. Supply chain risk is complicated, it’s changing quickly, and the defensive measures often involve multiple teams which drives up the complexity. The insights captured throughout this book are absolutely necessary for the state of software security today and having the proper context and frame of the problem space as you read it will help get the most of it.”
―Robert Wood, CISO of Centers for Medicare and Medicaid (CMS)
“This is a very good book. It achieves something that I don’t think anyone else has even attempted: provide an encyclopedic account of guidelines, best practices, regulations, and current efforts to secure the software supply chain. The best aspect of this book is that someone (like me) who is primarily involved with just one aspect of software supply chain security can benefit from a well-informed treatment of the subject from different aspects, yet still have a reference tool to return to later, when the need arises to learn about other topics within this already vast discipline.”
―Tom Alrich
From the Back Cover
Explore the cybersecurity implications of the interconnected software supply chain
In Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, a team of dedicated information security executives and professionals delivers an incisive and essential new treatment of software supply chain security. In the book, you’ll find real-world examples of how to defend your own organization against attack. It includes coverage of topics ranging from the history of the software transparency movement to software bills of materials and high assurance attestations in a rapidly evolving software landscape.
The authors explain the background of attack vectors that are becoming increasingly vulnerable, including mobile and social networks, banking and retail systems, and even the critical infrastructure and defense systems upon which we all rely. You’ll discover how you can defend against threats to these networks and explore use cases and practical guidance for both software consumers and the suppliers who support them.
A can’t-miss resource for cybersecurity and application security professionals, Software Transparency will also earn a central place on the bookshelves of professionals working in industrial control system security, cloud security, mobile security, DevOps, and DevSecOps. The book offers extensive coverage of:
- Firmware and embedded software
- Cloud and connected APIs
- Industrial control systems
- Internet of Things-connected devices
- Federal and defense software supply chain initiatives
- Software for mobile devices
About the Author
CHRIS HUGHES is the co-founder and Chief Information Security Officer of Aquia. He is an Adjunct Professor for M.S. Cybersecurity programs at Capitol Technology University and the University of Maryland Global Campus, and a co-host of the Resilient Cyber Podcast.
TONY TURNER has 25 years’ experience as a cybersecurity engineer, architect, consultant, executive, and community builder. He is the Founder of Opswright, a software company creating solutions for security engineering in critical infrastructure and leads the OWASP Orlando chapter.
View on Amazon