Croot Blog

Home About Tech Hobby Archive

⚠️

이 블로그의 모든 포스트는 Notion 데이터베이스를 자동 변환하여 작성 되었습니다.
따라서 문서에 따라 깨져 보일 수 있습니다.
더 많은 내용이 궁금하시다면 👀 Notion 보러가기

SW 공급망 보안 가이드라인

[240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf](https://prod-files-secure.s3.us-west-2.amazonaws.com/8daffe33-d95b-4c96-91e6-1b899bcdb2d7/0f5f0886-db60-4a61-8e90-912aeea997fd/240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29_SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88_%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIAZI2LB466TMVO2QTY%2F20260306%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260306T073819Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEBcaCXVzLXdlc3QtMiJGMEQCIHnyOwSJz%2FJLibXiZWLqi9Q%2FNTjWZbiqgCxePJbyYb2AAiBZGufSlbrq%2FAcKL0tHTCi%2F%2Bf%2FzYUUwUx8GeWHLZggkPyqIBAjg%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDYzNzQyMzE4MzgwNSIMwOMEJf8bv4qVJ%2B26KtwDpFd2Njmj5t45wua6IhYG5i9tVZiscJinJvcwBejzuUIa9TVg9g4FdbuNRGUo%2BpfGdKnkERLOjcvBiGKleHpqE7mAWyD4W8P2%2FCbS96VLllnFKjxw00cFlpMufoVaOZQ0FcGlj2evLdHRlN8jBnPWrWMscTASed7mZYiNzVYbObQEDGMW78qg08oq7b%2B60v8Dh7s4czXwIDONQGh9qydtr9sx4ACWfGhQ0OBWmBXuY8ICiWOZbuQA21KI7n4JvRuIVPR7tG%2BAQ14%2BeEu26PkkK6bzExdsX0cNBnUisZlln3zbyTAUVUheruiwcQPu539XaDId4QiekkyCVUAcF%2FIjP9tA%2FKNlzUiDquKBnBjAk4T9pnkWFezhVvmrMUDrePQyINswhBXb48g8kpHmutO7M498cX%2BWwAAbg93x5Cx854EquS%2By0kytoOHjcAAMqAJJ%2FXoPjaRVUTuylPsApixzuoYKR42Iw%2FYUC%2Bhfr9Z1Z1Ub5cel%2Bh9vLoWrRoCIZkBtJyRDUQdfci3BtTU8gjSNTrmA7l7tKraHg5wddEj64%2FdFPbBO4TMjizCeumoWBav3mgJsYAAaeN%2Fnr7nOl7Ct2bgCh8PbuqeJddkRLf8JlfI8MFpsa4hpHgHD8oYwguupzQY6pgGgibbpJxnAAqT39xcrHMFkdKmJZwW%2B84JVVBkuMyg13UfcER0yK15ky4WOTNDx%2FSGDK31sEuntys9xdad7dtEZwVQGLW4DZEmcf5%2BPcTn%2FeMjXjo7%2FrUHDJL7L2JHZ8MktuauB0ivH%2FlS9PylpyYq%2FX3eZT8ljPArbtav1%2BI62fnbq%2BtbN%2F5GZ3AiVfCjIZR%2FY1BOuAuYJdCsalVrxMHwxpK89x3Km&X-Amz-Signature=80c214428230ddf166f8c3799f3a07ae701e1b958cb9e72efc5924d9aab55929&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

C-SCRM

  1. 전사 : 상위 수준의 전략, 실행계획 및 정책
  2. 프로세스 : 하위 수준의 전략, 실행계획 및 정책
  3. 운영 : 계획

구축방안

  • SSDF

신뢰성 확보 방안

  • SBOM