Croot Blog

Home About Tech Hobby Archive

SW 공급망 보안 가이드라인

[240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf](https://prod-files-secure.s3.us-west-2.amazonaws.com/8daffe33-d95b-4c96-91e6-1b899bcdb2d7/0f5f0886-db60-4a61-8e90-912aeea997fd/240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29_SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88_%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIAZI2LB4662HMKMFB6%2F20250823%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20250823T084814Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEND%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJHMEUCIF8hg1fXyTsKB%2Fja76CcL8t1U%2BgmTO89QfHRydhYHuxeAiEAnffiXnuMhfxdZg4mB09bltrf3ad1XxNeudX%2B6xkF54gq%2FwMIKRAAGgw2Mzc0MjMxODM4MDUiDK59XoTBqyd1d96J4SrcA0lP2nQoVS1Mq3O40eXNSnCn5Gv2nGz4c8Rc7FV8hO%2F6AryjBye%2FrPVK5bXdt60NDHM8TAtUsXDO2P%2FjXc09%2Fnwbm0ML7rXNRBA3pnPQasP8SGApwPGkWeCJ3A0TnUZyOg6LTV%2BKcaTZZfrfsFpqWsZPram8D6Ypp3rqtvgDlFO%2BZNF0yF1E36z79teheRCGcZfMwphWzeModTCTJaJBCMtGGU77ZWRSuJDjYar6VaxhdLY39b0ObTlotCtetTphf5fJh7%2BKtVgWw215IZcrANDftyJiWX%2FVEw%2BFICJf6r1dQDbdrag2MTXbC7YiwAPPHU7WPvQ7UhCdmA34oJTs3nMQlhoqdhYtspxMDCj6FTTaxpjjmA%2FUYG0cqR32Ed0rtXTukjverBw6D3eNZgUv3NZW4eJVaqjWJiHO%2Blj9Ng9Sa9rRVQPFR7nxQeiN5Iq%2BLVkYQI%2FhcEXXIQr59b0Rg85THLNiiGvAMTPWb%2BhAtwfkdiZC2Z%2FbZF70Ncm09rNbxPpcuUD0nvmT2kJHV%2FZf1QIT2mCoLTa7BiQHlTqzn9tM%2Bkp0UI0YLS05bMTuN%2BTyvGjwpdZjZQ0pwXj43lChWzqy7fQ0J1%2Bx6wkAYdlAgORn2sO5TAzybpldIWBIMIvxpcUGOqUBw%2Fi%2BoYf%2BFdGC9L78GBbGWmAxiu7AEV%2B0LkWzqrV5%2FO8P3O8DWthCCjEt6SGr0ZGTmb7X8E7OTNCRo3DZ7g%2B4hPYjraf2RtpX0WMxkjbNxkxS0xcWj8JThxND8tzFPGnCYoe1u2%2F0jH%2B%2BRKHuyju1G8p4Ob1cTOvAO05eMj0bAcSdAa95QLQnMC5UiMGBeHefIrLg%2FJHTL2l49kzDe%2F%2FGaWmx1oq0&X-Amz-Signature=c81637492b44178ce27d41204211bb53ce86a4ffe66be5c354d3ad3fb753fdf0&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

C-SCRM

  1. 전사 : 상위 수준의 전략, 실행계획 및 정책
  2. 프로세스 : 하위 수준의 전략, 실행계획 및 정책
  3. 운영 : 계획

구축방안

  • SSDF

신뢰성 확보 방안

  • SBOM