官术网_书友最值得收藏!

The need for software transparency

Software transparency provides development teams with a solid understanding of the components within their products. 

As of the time of writing, there are efforts to enhance the transparency of software through efforts such as the Software Bill of Materials (SBOM), led by the National Telecommunications and Information Administration (NTIA). An argument can be made that having an IoT product SBOM is a side-effect of having good development processes in place. 

Transparency also provides a valuable tool within the software supply chain. Providing users with an understanding of the third-party libraries used within a product can provide those users with important security knowledge.

For example, the OpenSSL Heartbleed vulnerability discovered in 2014 resulted in a worldwide, catastrophic security hole exposing the majority of the internet's web servers (read more at https://en.wikipedia.org/wiki/Heartbleed). Many companies did not even know about their exposure to this vulnerability, because they did not adequately track and follow the software supply chain into the end systems on which they depend.

The role of IoT security engineering organizations, therefore, needs to include tracking of open source and other security library vulnerability information, and ensuring the vulnerabilities are mapped to the specific devices and systems deployed in their organizations. Software transparency can enable this. 

主站蜘蛛池模板: 门源| 大方县| 隆尧县| 襄城县| 新巴尔虎右旗| 岗巴县| 宁强县| 邻水| 和硕县| 石泉县| 沁水县| 新营市| 申扎县| 二连浩特市| 来凤县| 大关县| 临颍县| 阿坝县| 邹平县| 宿州市| 平泉县| 乾安县| 谢通门县| 甘泉县| 瑞金市| 长汀县| 集贤县| 剑川县| 昌都县| 仁寿县| 廉江市| 宁夏| 平湖市| 辽宁省| 靖西县| 榆树市| 龙川县| 文成县| 大埔区| 黎川县| 美姑县|