Traceability and risk management in software supply chain cybersecurity: A systematic literature review and conceptual framework
Description
The growing complexity of software development, coupled with substantial reliance on third-party components, has expanded the scope of attacks targeting the software supply chain, compromising the integrity and traceability of software artefacts. This study aims to identify gaps in existing proposals for software supply chain cybersecurity and present a conceptual framework to address the identified shortcomings. A systematic literature review was conducted on traceability and risk management in software supply chain cybersecurity. In total, 29 primary studies were identified and analysed. The review reveals that current proposals address the software supply chain only partially. Based on this analysis, an agile conceptual framework is proposed to provide comprehensive support throughout the software supply chain. The framework is designed to record dependencies, build and test results, deployment events, processes and human interactions in an immutable manner, enabling subsequent verification and auditing by any interested party. Its modular design, role assignment, inclusion of operational metrics, and alignment with recognised standards and best practices are intended to support adaptation to organisations with different levels of maturity and resources. This paper presents a framework that addresses a gap in the literature by providing integrated support for traceability, risk management, and cybersecurity throughout the software supply chain.
Files
Institutions
- Universidad Rey Juan CarlosMadrid, Madrid