NIST writes the rules on software supply chain security for the United States government. Their Secure Software Development Framework, SP 800-218, is the document federal agencies cite when explaining why they require developers to track where their code comes from and who can touch it. Their supply chain risk management guide, SP 800-161, runs 300 pages.
Substack is the home for great culture


