Open Source Software Supply Chain Risks

Open Source Supply Chain Risks
Image by rawpixel.com on Magnific

The use of open source software can increase the potential for supply chain risks.  These risks should be managed by developing appropriate response strategies, policies, and procedures. This can include obtaining open source software from vetted sources, implementing Software Bills of Materials (SBOMs), maintaining provenance, and monitoring for vulnerabilities.

The Evolution of Open Source Software

Open Source Software (OSS) has become a cornerstone of modern software development.  It greatly enhances efficiency by reducing creation of extant functionalities for new products.  This usage has been accelerated through the use of generative AI.  These benefits however, create vulnerabilities to intrusions of malware. 

A recent article by Security Daily Review illustrates the severity of these security risks to developer ecosystems by Glassworm.  Glassworm is a malware being found in VSCode extensions. The malware JavaScript can perform remote commands, create a persistent backdoor on systems, and can exfiltrate data.

Open Source Vulnerability Management

Best practices for securing open source code supply chains include adopting secure software development practices and implementing zero trust principles.  Mitigation strategies include audits of open source components, automated scanning, and secure coding practices.  Third-party libraries should be continuously evaluated for vulnerabilities and policies should be implemented and enforced for proper use.  

NIST SP 800-161 Cybersecurity Supply Chain Risk Management

Federal agencies are mandated to follow the guidelines set forth in NIST 800-161 to enhance their cybersecurity posture, particularly concerning supply chain vulnerabilities. Non-federal entities may choose to adopt these guidelines voluntarily, especially if they work with federal agencies or handle sensitive government data.

NIST SP 800-161 provides a systematic approach for identifying, assessing, and managing cybersecurity risks throughout the supply chain. These risks include malicious code and compromised products from supplier networks.  The standard provides Cybersecurity Supply Chain Risk Management (C-SCRM) processes that can be adapted to fit the requirements of organizations.  It promotes the use of Software Bills of Materials (SBOMs) for managing and monitoring embedded software to manage risks.

Software Bills of Materials (SBOMs)

A software bill of materials (SBOM) is a machine-readable inventory that lists every software component, library, and dependency in a product.  It allows organizations to track elements, identify vulnerabilities, and mitigate supply chain risks.  It is useful for tracking purchased software, open source software, and proprietary software.  SBOMs allow organizations to scan for known vulnerabilities against threat databases and enable responses to emerging vulnerabilities.

The SBOM is an essential tool for software provenance.  Provenance refers to the metadata that documents the origin, development, and delivery of software components. This includes tracking where the software came from, who developed it, and any changes made throughout its lifecycle.

Supply Chain Security as a Team Responsibility

The state of open source code security is increasingly critical, as vulnerabilities in open source components can expose applications to significant risks.  The prevention of supply chain attacks requires the contribution of many individuals.  Responsibilities extend to development, procurement, operation, and maintenance. 

Personnel responsible for such activities should be screened and receive adequate training for the C-SCRM program.  The software development team should perform risk assessments when selecting open source software and ensure that code is obtained from vetted sources.  

CVG Strategy Cybersecurity Consultants

CVG Strategy can provide guidance and help your organization understand and implement contractually required NIST standards and CMMC.  We are dedicated to helping small businesses navigate federal regulations and contract requirements for Quality Management, CybersecurityExport Compliance, and Test and Evaluation. We can help you meet your information security management system goals.  CVG Strategy QMS experts can provide guidance for engaging in a ISMS and make it meet desired objectives.

Identify CUI Areas with CVG Strategy Signs

CVG Strategy provides signs to identify areas containing CUI and export controlled items. These signs should be posted at all facility entrances where access controlled or export controlled articles and technology are present.

Jamie Hamilton

Share this post

Secret Link