Croot Blog

Home About Tech Hobby Archive

⚠️

이 블로그의 모든 포스트는 Notion 데이터베이스를 자동 변환하여 작성 되었습니다.
따라서 문서에 따라 깨져 보일 수 있습니다.
더 많은 내용이 궁금하시다면 👀 Notion 보러가기

SW 공급망 보안 가이드라인

[240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf](https://prod-files-secure.s3.us-west-2.amazonaws.com/8daffe33-d95b-4c96-91e6-1b899bcdb2d7/0f5f0886-db60-4a61-8e90-912aeea997fd/240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29_SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88_%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIAZI2LB4666PHVIVTC%2F20260323%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260323T073413Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJHMEUCIDh8flfy093RiuZfKQgIR82T4Y760GM2Zi3VUNVy7YvwAiEA54uxbZRy8vF%2FSuxTe3ak7hy1Hg9WLPExtXZO3XfmYZAq%2FwMIeRAAGgw2Mzc0MjMxODM4MDUiDM%2BmVjuub9ezGEebbSrcA41tCoDAyJDNzuWxvZm8h41xQUzhkCSw44zSq%2BYdEFYn34agWBMEcVKvKSzIM7Tw3rN2yNj5IYc4mapEfypzUinFVWhxPbeH%2FQlq868GJ9sSeqRoM2RZbhmphPQ5%2BEBp0o%2FiOMKNcd3uEusKUCaKR7PeUl9LsqKzozgFoAT6HHUAK%2FdG0109lCnb87qaoe3E9v2FPnt5AGlh6W0vdu8HPwEowbnyfakMLWLv3zr2B1bbgicm3ohaBMbOeo86u%2BeXqLlSK036nI0Q8CMV2rWzpb174pmUP2UtTveUSs7WgWZDlLuDb3aG1eQNuX4J8zBBYvE1ch4naR1ZtPWv0EZ6QfK4QMD%2Bbvlc6R%2B8d8JhLecyxEpH%2FctJl6pdOeAQ9aIihlBygSCi4XLZr0RNwzWY%2FRGvTtcMPOVy34LTVGsKbQxbelh3IApHkFUB61QeoZK0aBjslnMglpstDEW7x5vZE95ValK8Ia6DUUIZNlbJb27XmzyRmTL%2FBCSMeo1lIv6%2Bd0uLdre%2BAxCYgFzRNP%2F9HIj9vq80iS6UpcOCqYHU%2FDfdry%2BQkuB3z9%2B7pYTB%2Ftl6RuxxIdWNd4TGa6QTR6esmGM1%2FQ5YTqzzPqF6aIJMibEGqn4hRWh5rwM3kWOHML3Vg84GOqUBlj0sL9qicnPqje6as4f67h9bSPvyuNLJSlgdbyGZZ82YDJIFBn3eTecPixXJqrjWHnalyKkIoZCcgCP7%2Bxs%2Bq2esZ%2FVa6%2Fh4P46Yhf8XWahsT71vaJWiiKKGahwgTLrMkmIAudsDsI6IW6DfrdLzqDC1KWfx6Ix%2B02QmNiMeNP0mzc1MRm0GHfcLMvEOVDgyTATe3c94oStkZ%2FptYZhhS7fvHjp6&X-Amz-Signature=9df2f604c702d16d45067e71ae3da6eb03cf6145970a14d08f716477453a840f&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

C-SCRM

  1. 전사 : 상위 수준의 전략, 실행계획 및 정책
  2. 프로세스 : 하위 수준의 전략, 실행계획 및 정책
  3. 운영 : 계획

구축방안

  • SSDF

신뢰성 확보 방안

  • SBOM