官术网_书友最值得收藏!

The need for software transparency

Software transparency provides development teams with a solid understanding of the components within their products. 

As of the time of writing, there are efforts to enhance the transparency of software through efforts such as the Software Bill of Materials (SBOM), led by the National Telecommunications and Information Administration (NTIA). An argument can be made that having an IoT product SBOM is a side-effect of having good development processes in place. 

Transparency also provides a valuable tool within the software supply chain. Providing users with an understanding of the third-party libraries used within a product can provide those users with important security knowledge.

For example, the OpenSSL Heartbleed vulnerability discovered in 2014 resulted in a worldwide, catastrophic security hole exposing the majority of the internet's web servers (read more at https://en.wikipedia.org/wiki/Heartbleed). Many companies did not even know about their exposure to this vulnerability, because they did not adequately track and follow the software supply chain into the end systems on which they depend.

The role of IoT security engineering organizations, therefore, needs to include tracking of open source and other security library vulnerability information, and ensuring the vulnerabilities are mapped to the specific devices and systems deployed in their organizations. Software transparency can enable this. 

主站蜘蛛池模板: 静宁县| 墨竹工卡县| 泰和县| 济源市| 中超| 宁陵县| 萨嘎县| 栾川县| 洪雅县| 承德县| 余江县| 汶川县| 招远市| 玉屏| 县级市| 上杭县| 兰坪| 九台市| 绿春县| 务川| 南安市| 盐亭县| 剑河县| 游戏| 沙河市| 舟山市| 嘉祥县| 秭归县| 丹棱县| 崇阳县| 丹棱县| 临桂县| 仪征市| 富蕴县| 樟树市| 锡林郭勒盟| 顺昌县| 六安市| 濮阳市| 恩施市| 郓城县|