As software supply chains grow more complex, so do the associated security risks. In response, CIOs are seeking to implement data-driven supply chains that maintain total transparency regarding where each software component originated.

John Abel, CIO of cloud networking provider Extreme Networks, argued that vulnerability management is key to this challenge, and given the depth of modern software ecosystems, IT teams can’t be too curious. Abel told SDxCentral that data on a piece of software’s development country of origin, individual components and any hands that touched it can be signs of the software’s health and safety.

Although existing automated response and vulnerability scanning technologies, for example, can analyze third-party software to understand those contents from a security point of view, it's an "area that I think is still evolving," Abel said. "There is going to be a more intense focus, I think, from a lot of companies and a lot of CIOs in terms of understanding where their software has actually come from."

Traditionally, security teams employ a decent number of security analysis tools to discover software vulnerabilities in cloud or on-premises environments. "You're always constantly polling your supply chain and looking at all of the systems you use, whether it's Salesforce or Oracle or any third-party product," he said.

And while vendor management used to offer assurances that a software vendor is providing secure products, "you have to go way, way beyond that now," Abel noted. "You [need] to have scanning tools, you [need] to have things that can actually go inside of that organization, and they [need] to be willing to work with you to ensure you have a sense of confidence that they're as secure as you need them to be," especially with cloud-based software.

Which software vendor is your weakest link?

Trusted delivery services, on the other hand, offer additional software supply chain security via authenticity statements, and Abel touted the vendor's investment in this area. "Our software leaves our environment to you, as a customer, [and] it's completely secured and trusted," he explained. "No one can touch that code."

To that point, software supply chain data that offers a historical understanding of software components "has become very valuable," Abel said, and Extreme plans to remain "very focused" on this area throughout the next fiscal year.

This supply chain problem – vulnerabilities in third-party software – "is very front and center if you ask me and most CIOs today," he added. "Do I have confidence that the third-party software, my supply chain of software vendors, is secure? Because I am only as secure as my weakest link – my weakest vendor."