Skip to main content

2024 | OriginalPaper | Buchkapitel

Software Supply Chain Resiliency at Scale

verfasst von : V. Lakshmi Narasimhan, S. Ramaswamy, O. Mphale

Erschienen in: ICT: Applications and Social Interfaces

Verlag: Springer Nature Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Software businesses are increasingly dependent on supply chains from several providers to receivers, like traditional business. Real-world software systems of today contain hundreds (perhaps thousands) of smaller programs and modules from various world-wide sources. During a cyberattack, these software supply chains get disrupted. Industry-wide standards that offer guidance to ensure supply chain security and integrity are yet to mature and are still evolving. In this paper, we address the need for a structured, organized approach to compile and automate the decisions related to software supply chain vulnerabilities and pave the way to simultaneous enable organizational knowledge capture and reuse. Specifically, this paper addresses broadly classifying supply chain vulnerabilities to define a scalable solution for software supply chain vulnerabilities, its modeling and evaluation, related metrics, and possible detection and response.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat New Supply Chain Levels for Software Artifacts (SLSA++) Survey Reveals Real-World Developer Approaches to Software Supply Chain Security (openssf.org) New Supply Chain Levels for Software Artifacts (SLSA++) Survey Reveals Real-World Developer Approaches to Software Supply Chain Security (openssf.org)
4.
Zurück zum Zitat Sobb T, Turnbull B, Moustafa N (2020) Supply chain 4.0: a survey of cyber security challenges, solutions and future directions. Electronics 9(11):1864 Sobb T, Turnbull B, Moustafa N (2020) Supply chain 4.0: a survey of cyber security challenges, solutions and future directions. Electronics 9(11):1864
5.
Zurück zum Zitat Briano E, Caballini C, Revetria R (2009) Literature review about supply chain vulnerability and resiliency. In: Proceedings of the WSEAS international conferences on system science & simulation in engineering Briano E, Caballini C, Revetria R (2009) Literature review about supply chain vulnerability and resiliency. In: Proceedings of the WSEAS international conferences on system science & simulation in engineering
9.
Zurück zum Zitat Hudnurkar M, Deshpande S, Rathod U, Jakhar SK (2017) Supply chain risk classification schemes: a literature review. Oper Supply Chain Mgmt 10(4):182–191CrossRef Hudnurkar M, Deshpande S, Rathod U, Jakhar SK (2017) Supply chain risk classification schemes: a literature review. Oper Supply Chain Mgmt 10(4):182–191CrossRef
10.
Zurück zum Zitat Peterson JL (1981) Petri net modeling and analysis. Addison-Wesley Peterson JL (1981) Petri net modeling and analysis. Addison-Wesley
11.
Zurück zum Zitat Lahmar A, Chabchoub H, Galasso F, Lamothe J (2018) The VESP model: a conceptual model of supply chain vulnerability. Intl Jol Risk Conting Manag 7(2):42–66. ff10.4018/IJRCM.2018040103ff.ffhal-01968778 Lahmar A, Chabchoub H, Galasso F, Lamothe J (2018) The VESP model: a conceptual model of supply chain vulnerability. Intl Jol Risk Conting Manag 7(2):42–66. ff10.4018/IJRCM.2018040103ff.ffhal-01968778
12.
Zurück zum Zitat Beamon BM (1998) Supply chain design and analysis: models and methods. Int J Prod Econ 55(3):281–294CrossRef Beamon BM (1998) Supply chain design and analysis: models and methods. Int J Prod Econ 55(3):281–294CrossRef
Metadaten
Titel
Software Supply Chain Resiliency at Scale
verfasst von
V. Lakshmi Narasimhan
S. Ramaswamy
O. Mphale
Copyright-Jahr
2024
Verlag
Springer Nature Singapore
DOI
https://doi.org/10.1007/978-981-97-0210-7_37