RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityFebruary 23, 2023

How C-SCRM could fill the gaps on supply chain security

The new CISA office could make a big difference — and even lead to a new discipline dedicated to software supply chain security

Matt Rose, Field CISO at ReversingLabs.Matt Rose
FacebookFacebookXX / TwitterLinkedIn
LinkedIn
blueskyBluesky
Email Us

Main Story

IntroGet on the same page for supply chain guidanceWe're all in the supply chain security fight togetherShon Lyublanovits: A leader who "gets it"A new supply chain security discipline could emerge

Software supply chain security is finally getting the attention it deserves with the recent announcement of a new supply chain risk management office in the Cybersecurity and Infrastructure Security Agency (CISA). The goal of the office is an ambitious one. It wants to help agencies, industry and other partners put into practice the deluge of guidelines and policies pouring from the federal government on Cyber Supply Chain Risk Management (C-SCRM).

The problem up to now is that no one is making the effort to define what supply chain risk management is. In the industrial world, everyone has a good idea what a supply chain is. But for software supply chains, the guidance has been vague.

For example, in 2020, the Government Accountability Office (GAO), which is Congress's watchdog on government operations, identified seven key practices for managing supply chain risk. Then it examined 23 agencies to see how those practices were being implemented.

The results were disappointing. None of the agencies had implemented all the practices, and 14 hadn't implemented any of them at all. The practice implemented by the most agencies — six of the 23 — was establishing a process for conducting a C-SCRM review of a potential supplier. One practice was ignored by all the agencies: establish a process for conducting agency-wide assessments of supply chain risks.

The GAO noted that the agencies cited a number of factors limiting their implementation of the seven foundational practices of managing supply chain risk, but the most commonly cited factor was a lack of federal C-SCRM guidance.

This new office for supply chain security has the potential to make that guidance concrete and consistent, filling a gap in private and government initiatives. Here's why it's a great first step.

Video: C-SCRM: Much-needed definitionSpecial: NIST CSF 2.0 and C-SCRM for Software Risk Management

Get on the same page for supply chain guidance

For the first time, a dedicated agency is going to take the reins and nail down what software supply chain security risk management means — and answer some key questions, such as what should the process to implement C-SCRM look like, how should risk be managed for software development across any organization, and whether it be a government entity, industrial vertical, or small- or medium-sized business.

Another question the office should address is how should self-attestation of software work? Does it mean that a vendor can say, "My software is secure" and a user should just believe them, or should an attestation include a software bill of materials (SBOM) or a checklist of things the vendor has to attest to?

An additional area where the office could make a worthwhile contribution is in SBOM guidance. How should they be delivered? Should they all be in the same format? The office has an opportunity to deliver overarching guidance that can clear up a lot of the noise around SBOMs now.

We're all in the supply chain security fight together

The new C-SCRM office will benefit from changing attitudes between acquirers and vendors, who are beginning to acknowledge there might be problems with how they deliver software and are more willing to participate in supply chain security conversations.

Jon Boyens, deputy chief of the computer security division at U.S. Department of Commerce’s National Institute of Standards and Technology (NIST), told the Federal News Network:  

I actually think we’re kind of in the midst of relationship changes between acquirers and suppliers. Ten years ago, the reception I received from some industry colleagues, typically IT vendors, was, ‘Go pound sand. Here’s my product. You get it if you want it. If not, it’s a global market, we’re going elsewhere.’ That’s changed.

Jon Boyens

Boyens added that the relationship between industry and government has also evolved. Government is getting more accommodating to industry's concerns and treating cybersecurity as a partnership:

"I think often government gets in the habit of asking for a lot of information that it doesn’t use, and asking for a lot of requirements that costs more money, that are unnecessary. I think we’re getting there. We’re not yet. It’ll be a few more years, but we’re on the right road.”

Jon Boyen

Shon Lyublanovits: A leader who "gets it"

To head up the new C-SCRM office, CISA has chosen Shon Lyublanovits, an old General Services Administration hand. The GSA is the procurement agency for the federal government. From Lyublanovits' remarks following her new appointment, it appears that she "gets it" when it comes to the current state of software supply chain risk. Lyublanovits said during a Jan. 30 event hosted by GovExec:

We’ve got to get to a point where we move out of this idea of just thinking broadly about C-SCRM and really figuring out what chunks I want to start to tackle first, creating that roadmap so that we can actually move this forward.”

Shon Lyublanovits

Under the umbrella of guidance, Lyublanovits' new office will be offering new training courses on supply chain risk management later this year. It's also going to start a series of roundtables on operationalizing C-SCRM. They will include three tracks — one for federal employees, one for industry, and another for state, local, tribal and territorial governments.

Noting what she said plagued agencies in the past were where to start and how to get buy-in.

One, where to start? And two, how do I have that conversation with my leadership? If you don't have leadership buy-in, you can't get funding. You can't go hire people to help you do what you want to do.

Shon Lyublanovits

A new supply chain security discipline could emerge

In ReversingLabs' new special report, The Evolution of Application Security, I posited that software supply chain security needed to be recognized as distinct:

Software supply chain security needs to be recognized for what it has become: A separate discipline within the application security ecosystem.

With C-SCRM and supply chain security finally getting the recognition it deserves, new hires may be cast in new roles. Instead of just being a penetration tester or an application security professional, a new discipline may emerge for supply chain security professionals.

See Matt Rose's related ReversingGlass explainer: C-SCRM: Much-needed definition for supply chain policy and processes.

Tags:AppSec & Supply Chain Security

More Blog Posts

Main Story

IntroGet on the same page for supply chain guidanceWe're all in the supply chain security fight togetherShon Lyublanovits: A leader who "gets it"A new supply chain security discipline could emerge

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagram
Matt Rose
mind the gap printed on subway ground

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get key insights into why Gartner® said binary analysis is a must-have control in its recent CISO Playbook for Commercial Software Supply Chain Security.
  • Update your understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security,

Instagram
YouTubeYouTube
blueskyBluesky
Spectra Detect
for scalable file analysis,
Spectra Analyze
for malware analysis and threat hunting, and
Spectra Intelligence
for reputation data and intelligence.

This video is blocked because of your cookie preferences.

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Related

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the riseFrontier AI agents: Only as safe as their containmentAI domain takeover takeaway: Focus on the harness not the model

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Learn More about OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

Frontier AI agents: Only as safe as their containment

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Learn More about Frontier AI agents: Only as safe as their containment
Frontier AI agents: Only as safe as their containment

AI domain takeover takeaway: Focus on the harness not the model

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Learn More about AI domain takeover takeaway: Focus on the harness not the model

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
AI domain takeover takeaway: Focus on the harness not the model
Robot agent
AI guardrails
Frontier AI controls