Supply Chain Security

Dependencies, SBOMs, build provenance and artefact signing.

6Questions
11Flashcards
9Terms
Terminology

9 terms in this topic

practice

Artifact Signing

Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.

pattern

Build Provenance

A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the b…

practice

Build Provenance

A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an arte…

concept

CI Secret Exposure Surface

The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a…

concept

Dependency Confusion

A build resolving an internal package name from a public registry because the package manager prefers the highest version across all configured sourc…

case-study

Equifax 2017: A Known Patch and an Expired Certificate

An unpatched framework vulnerability provided entry, and an expired certificate on a monitoring device meant the exfiltration went undetected for months.

practice

Reachability Triage

Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by…

tool

Software Bill of Materials

A machine-readable inventory of every component and dependency in a piece of software, including transitive ones, used to answer exposure questions q…

practice

Supply Chain Attestation

A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.

Security Architecture

Neighbouring topics

Security Architecture

General material on securing an architecture.

4 quiz 18 cards 15 terms

Authentication

Establishing who a principal is, and how strong that claim needs to be.

4 quiz 5 cards 3 terms

Authorization

RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.

5 quiz 8 cards 6 terms

OAuth 2.0 & OIDC

Delegated authorisation, and the identity layer that makes login safe.

4 quiz 5 cards 3 terms

Tokens & JWTs

Stateless validation, revocation, and pinning the algorithm.

6 quiz 10 cards 5 terms

Identity & Access Management

Workload identity, roles, permission boundaries and usage-based review.

4 quiz 9 cards 6 terms

Secrets Management

Runtime injection, dynamic credentials and rotation applications survive.

5 quiz 8 cards 4 terms

Encryption

At rest, in transit, and at the application layer — three different threats.

5 quiz 10 cards 2 terms

Key Management

Rotation, separation of duty, envelope encryption and crypto-shredding.

4 quiz 8 cards 5 terms

Zero Trust

No implicit trust from network position; authorise every request.

6 quiz 8 cards 3 terms

Threat Modelling

Walking trust boundaries with STRIDE before anything is built.

5 quiz 9 cards 3 terms

OWASP Risks

The recurring web and API risk classes, several of which are design flaws.

3 quiz 8 cards 2 terms

Secure API Design

Object-level authorisation, input validation and safe error responses.

6 quiz 10 cards 3 terms

Network Security

Segmentation, egress control and limiting lateral movement.

5 quiz 6 cards 4 terms

Auditability

Tamper-evident, attributed records that survive async boundaries.

4 quiz 6 cards 3 terms

Compliance Frameworks

SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.

5 quiz 9 cards 2 terms

Privacy Engineering

Minimisation, purpose limitation, and erasure that is implementable.

4 quiz 10 cards 2 terms

Data Classification

Knowing which fields are regulated, because every control depends on it.

5 quiz 7 cards 3 terms

Security Incident Response

Detection, scoping, containment and notification clocks.

5 quiz 11 cards 3 terms