Skip to content

Latest commit

 

History

History
56 lines (38 loc) · 4.24 KB

File metadata and controls

56 lines (38 loc) · 4.24 KB

The Software Supply Chain Stages

People Local Reqs Source Code Integration Deployment Runtime Hardware DNS Services Cloud
Developers IDE Languages SCM providers Build solutions Servers Embedded PC URL SaaS solutions CDN
QA team SCV Frameworks Pull requests Deployment platforms Operating systems PCB hostname Third party APIs Cloud services
DevOps team Local tests Libraries Secrets mgmt Releases Webservers USB dongle Payment gateways
Package Maintainers Git repos Package Managers Git repos Functional tests Application servers GPU/CPU Identity Providers
Page Builders Packages Security tests Web engines Analytics
Open source API test frameworks Databases Proxies
Proprietary Code Unit tests
People Local Reqs Source Code Integration Deployment Runtime Hardware DNS Services Cloud

Services

This refers to the process of identifying and describing the external services that a application relies on in order to function properly. These third-party services can include anything from authentication and authorization services to payment processing and analytics tools.

What's in scope?

  • third party SaaS solutions
  • third party APIs or data
  • payment processors/gateways
  • identity providers
  • analytics & tracking

Examples

Payment gateways & processors

SaaS solutions examples

Analytics & tracking examples

Who owns it?

  • CloudOps team
  • Marketing team

How do I secure it?

  • Centralized audit logs
  • Vendor key management
  • Content security policy
  • Just in time access control