Blog | G5 Cyber Security

CISA, NIST published an advisory on supply chain attacks

CISA and NIST published a report on software supply chain attacks that shed light on the associated risks and provide instructions on how to mitigate them. The recent SolarWinds demonstrated how dangerous could be a supply chain attack and how hard is to detect it. The report recommends the use of the National Institute of Standards and Technology Cyber Supply Chain Risk Management framework and the Secure Software Development Framework (SSDF) to identify, assess, and mitigate risks associated with this type of attacks. Most of these attacks are attributed to well-resourced attackers and APT groups.”]

Source: https://securityaffairs.co/wordpress/117286/hacking/cisa-nist-supply-chain-attacks.html

Exit mobile version