Check out the New SAFECode Blog
SAFECode has released, “Software Integrity Controls: An Assurance-Based Approach to Minimizing Risks in the Software Supply Chain.” As the first industry-developed guidance on software integrity practices, this paper builds upon the Software Supply Chain Integrity Framework released in July 2009 and provides actionable recommendations for minimizing the risk that vulnerabilities could be inserted into a software product during its sourcing, development and distribution.
Download "Software Integrity Controls: An Assurance-Based Approach to Minimizing Risks in the Software Supply Chain." (pdf) 2.3M
After you've read the paper, send us your comments.
SAFECode has released its fourth member report, "Software Supply Chain Integrity Framework." The paper outlines the first industry-driven framework for analyzing and describing the efforts of software suppliers to protect software from the insertion of vulnerabilities as it moves along the global supply chain.
Download Software Supply Chain Integrity Framework Paper (pdf) 1.4M
SAFECode.org is a comprehensive online resource for news and information about software assurance. SAFECode members include Adobe, EMC Corporation, Juniper Networks, Inc., Microsoft Corp., Nokia, SAP AG, and Symantec Corp.
SAFECode Releases "Software Integrity Controls: An Assurance-Based Approach to Minimizing Risks in the Software Supply Chain.”
The new report provides actionable recommendations for minimizing the risk of vulnerabilities being inserted into a software product during its sourcing, development and distribution. More
SAFECode Adds Adobe as Newest Member
As a SAFECode member, Adobe will join with subject matter experts to identify and share proven best practices for software assurance, promote broader adoption of software assurance best practices into the cyber ecosystem, and work with businesses, governments and critical infrastructure providers to leverage these practices to manage enterprise risks. More
SAFECode Releases Software Supply Chain Integrity Framework
New Paper outlines the first industry-driven framework for analyzing and describing the efforts of software suppliers to mitigate the potential that software could be intentionally compromised .... More