Cybersecurity practitioners started this year with the struggle of addressing the SolarWinds supply chain attack, and now the Log4j vulnerability is another wake-up call for the need to set up long-term risk-management strategies.

Earlier this month, Apache disclosed and patched a remote code execution vulnerability in its popular Java logging library, which is used in nearly every enterprise app and service from vendors including Microsoft, Twitter, Amazon, and Apple, among others. Since then threat researchers had seen attempted exploits of more than 48% of corporate networks globally, according to Check Point.

“The fact of the matter is that Log4j’s vulnerability is just the wake-up call we needed,” Forrester analysts wrote in a recent blog post. “Software has bugs — sometimes severe security bugs, with significant potential consequences.”

The analysts suggest managing open source risk with tools and processes including a software bill of materials (SBOM), software composition analysis, and third-party risk management. 

Call Attention to Open Source Maintenance 

Log4j is not the first vulnerability found in open source software (OSS), but it could be the most consequential one since the popular open source logging tool is used by millions of servers, Forrester analysts wrote.

“Risk management of OSS has not kept pace with the OSS usage boom among public and private sectors,” they warned, adding that organizations should treat open source software as a third-party risk.

In addition, software supply chain attacks increased by 6.5 times since 2004 — at least 70% of which targeted open source. But the Federal Financial Institutions Examination Council has not updated its open source software risk management guidance in 16 years, according to Forrester.

Sumo Logic CSO George Gerchow concurred on the importance of open source software maintenance. Sumo Logic is “constantly patching and looking at the risk of open source,” he said in an interview prior to the discovery of Log4j.

However, open source software shouldn't be blamed for the Log4j vulnerability and attempted exploits, he added. “I personally think that open source is getting a black eye over this situation and it’s not fair,” Gerchow wrote in response to questions. “For Sumo Logic, we’re going to continue to lean into open source.” 

SBOM Brings Visibility Into Software Assembly

Not long after the Log4j vulnerability was discovered, security analysts noted that “a set of accurate SBOMs would help organizations target their responses to the vulnerable components in their environments,” Forrester analysts wrote.

An SBOM is a list of all the components, libraries, and modules that are required to build a piece of software. It includes both closed and open source code, and it details the supply chain relationships between the components to enable software transparency and security analysis.

“SBOM is a recipe for how the sausage is made in terms of software,” Gerchow explained. "SBOM will help tremendously to let the world know how the secret sauce is made. It’s critical to have visibility into the software assembly so we know what’s open source and what is not. This is why full-stack observability is so important."

SBOMs also can help address supply-chain threats. "It's something that everyone should have already been doing," Gerchow said. "You should always know how the sausage is made with anyone that you trust to partner with, any vendor that you do business with."

The SolarWinds hack reminded organizations “you're only as good as the weakest link in your supply chain,” he added.

After SolarWinds, federal agencies began working on software-related standards and guidelines called for in U.S. President Biden’s May cybersecurity executive order. 

The National Telecommunications and Information Administration also asked for feedback as it works to define a minimum SBOM, per Biden’s executive order.

Speed Up Cloud Transition

On top of the open source maintenance and SBOMs, Gerchow urged organizations to speed up their cloud migration.

 Log4j "highlighted the need to get rid of infrastructure and to speed to the cloud," he added. “The only reason we even have collectors is for on-premise tools.”