Artwork

Content provided by John Verry. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by John Verry or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Ep 116: What is an SBOM & Why Are My Customers Suddenly Asking for One?

36:45
 
Share
 

Manage episode 361645734 series 3260966
Content provided by John Verry. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by John Verry or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
With the release of President Biden’s Executive Order 14028 on “Improving the Nation’s Cybersecurity” from May 2021 the US public and private sectors have been alerted to the significant cybersecurity risks within our software supply chain. As of the March 2023 release of the National Cybersecurity Strategy, which will shift liability for software products and services to promote secure development practices, it’s evident that software security needs to be elevated across all organizations.
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Tim Mackey, Head of Software Supply Chain Risk Strategy at Synopsys, to explore what better software supply chain security means for software development and more.
In this episode, join us as we discuss:
· Defining an SBOM what it can include depending on stakeholder needs
· The value of SBOMs for both software developers and their clients
· Market drivers for improved software supply chain security
· Software composition analysis and its role in mapping dependencies and identifying vulnerabilities within code
· How the NIST Secure Software Development Framework (SSDF) supports initiatives to improve software supply security
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
  continue reading

142 episodes

Artwork
iconShare
 
Manage episode 361645734 series 3260966
Content provided by John Verry. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by John Verry or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
With the release of President Biden’s Executive Order 14028 on “Improving the Nation’s Cybersecurity” from May 2021 the US public and private sectors have been alerted to the significant cybersecurity risks within our software supply chain. As of the March 2023 release of the National Cybersecurity Strategy, which will shift liability for software products and services to promote secure development practices, it’s evident that software security needs to be elevated across all organizations.
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Tim Mackey, Head of Software Supply Chain Risk Strategy at Synopsys, to explore what better software supply chain security means for software development and more.
In this episode, join us as we discuss:
· Defining an SBOM what it can include depending on stakeholder needs
· The value of SBOMs for both software developers and their clients
· Market drivers for improved software supply chain security
· Software composition analysis and its role in mapping dependencies and identifying vulnerabilities within code
· How the NIST Secure Software Development Framework (SSDF) supports initiatives to improve software supply security
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
  continue reading

142 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide