Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialMost applications are composed of a ton of open source and the numbers associated with that, depending on what industry analyst you look at or read or, a fan of, 40 - 80% of any modern piece of software application is open source. Okay let's say we're on the high end. We have 20%. Even if we choose 80% coverage or 80% and you roll out a software composition analysis, you look at the open source code, you look at the vulnerabilities in those, there's still 20% of risk.
How can you trust the security of your package, the compiled piece of software application if there's still a 20% potential for risk? It's just like the house. I trust the security of my house, the doors, some windows, but one window is a problem. That's 20%. That's all it takes. That is the open window or the unlocked door into risk.
How did that get in there? You could do the best job possible with all sorts of application security testing from, the code to the running state, even to the tooling. That's a three. Your first party code, the code you're writing, you're making sure that's secure. You have a very robust program around SAST or scanning the core source code.
You have a runtime testing program with DAST to look for vulnerabilities at runtime. You're locking down your development CI/CD pipelines with the IDEs, the code repos, the build systems, the CI orchestration layer. But there's still potential for a gap. And for trust to be complete with your software supply chain security, you have to look at the whole package.
There has to be a final exam to ensure you didn't miss something, because that is the biggest thing that happens is you miss something. You spent time, energy, you had the smartest minds, but let's face it. Software is complicated. Applications in this modern CI/CD DevOps ecosystem are complicated. And to make sure that you're doing everything correctly is, I think, a little bit of a, I don't know, a dream?
So testing this final package to make sure all that work you did is vitally important. Don't leave a window open when you're locking everything else. Because you know what? Nefarious dudes, as I like to say, have unlimited time and unlimited resources to find that open window. They're going to try them all, and if you don't lock them all down, you cannot trust your software.
Trust is complete. Make sure you look at the complete picture. I'm Matt Rose. This is ReversingGlass. Have a great day, everybody.

