Not-for-profit organisation the Software Assurance Forum for Excellence in Code (SafeCode) today announced a new industry-led resource designed to help suppliers prevent software being deliberately compromised during sourcing, development or distribution.
The Software Supply Chain Integrity Framework (PDF) was jointly developed by SafeCode members, including SAP, EMC, Symantec, Microsoft, Nokia and Juniper Networks.
SafeCode said that the framework is designed to address so-called supply chain attacks, in which malicious code is intentionally inserted into software during its development or maintenance.
Secure code development is only one element of software assurance, however, and the software creation and delivery processes must also include integrity controls to enable vendors to deliver uncompromised products, according to SafeCode.
"While SafeCode members have individually implemented software integrity practices, this is the first time that the industry has come together to establish a common framework for ensuring the integrity of software through the global supply chain," said Paul Kurtz, executive director of SafeCode.
"This framework will serve as the foundation for subsequent work aimed at identifying and analysing software integrity best practices, and represents a critical step forward in the industry's efforts to advance software assurance."
Industry group tackles software supply chain attacks
By
Phil Muncaster
on Jul 22, 2009 8:34AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Kaseya Dattocon APAC 2024 is Back

Channel can help lead customers to boosting workplace wellbeing with professional headsets
Ingram Micro Ushers in the Age of Ultra
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report