Croot Blog

Home About Tech Hobby Archive

SW 공급망 보안 가이드라인

[240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf](https://prod-files-secure.s3.us-west-2.amazonaws.com/8daffe33-d95b-4c96-91e6-1b899bcdb2d7/0f5f0886-db60-4a61-8e90-912aeea997fd/240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29_SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88_%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIAZI2LB4662WBUFXYP%2F20250610%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20250610T144943Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEOT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJIMEYCIQDCH0w%2BzPwYrCid0mId0rnJN%2Be0NZ%2BYIl%2FWUvjD%2F6HxAAIhAJ18AJSuTGDA%2FOn9oFmFoh8axVJXe2ldamU2Xt5DjQ96KogECL3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQABoMNjM3NDIzMTgzODA1IgxRODmOm7Ns5rV7DHYq3AO4vXxzoYa63MBqWnuegsCz3etMe%2FQL%2B5jeAv5FCekGpbPZUNJPBXe9sGYX25zzrqlGSSQnnyLKiJ%2Fx%2F1aut05AIoxZ0LM3%2B6svhcE9R%2B38gnQChjHrxYQlRXu6aaY7JiI54CjOqkE1y1aJGbj7wSzHzH1iaZ9pkS3WS49jWhYdn1VgsoUY8Os4gjTXWWty4t7dPLsdk6tCza%2Fh0St73%2FIjLNQM%2BHA6tM82fCeI8kFvu%2FLXtUCu4tQ6HT8BDLyJ98uX7cUhldJdyryN2ggnh%2FZ%2Fu57EGSGQ642aIaT8rhu2m%2FBFwmrzL6A82JLFD%2BdFmT6VceNJPjVZ1GJsq8TJULlHf%2FsAIJYmc%2BpqSnnU2oF4xln7dD2gj6lEBeIVqobsdhTnh%2FadSyqHF1JcQco%2FzrrKkgO12I9L4EgCoYkqomDnozpaeMKlPIExAlqrgWh1PgBTRPb6wgxBbNEyHGvXMEZ7yyJvrX7WWfwaw7Y6XSIsRt85amQmkw5zzNvFzpEaHBmUldhK4OcxC66V2BLCEpA4Ub64%2Bv39C1kNksXuCsXoz01qnQePB2k%2FfO7lI9j3aWIFOOegp20qkyIIOVKNWIUE4RSk2YuNTBIpyO34q6Yq58AqWdvhZRJtPB7KtDDuvqDCBjqkAd6i4ysJZ9oOxOvGMmvG4RaTVy9IF0Fq0%2Buvx%2FFNttAlpqvLUrf0Yl5xkEYOQXLlQSTmlaWGWMs5%2Fju0fCAOwVwU1crjjifzUGFTv%2BdaIaQU1hkYrQLD8mmJa3da36gC7ehQe33gG6ltVfHXKFJKDxCzHJgc2jRLy%2B9SOam3WWPHWan%2BF1zplmpDBMpFmIzXNeS3SJSx431SKAR%2B67YmUVv3S%2FpJ&X-Amz-Signature=aee5f35408b8bffb4bf880fa705e3ce942755343ddbcbc64f6d9a0444d6b2426&X-Amz-SignedHeaders=host&x-id=GetObject)

C-SCRM

  1. 전사 : 상위 수준의 전략, 실행계획 및 정책
  2. 프로세스 : 하위 수준의 전략, 실행계획 및 정책
  3. 운영 : 계획

구축방안

  • SSDF

신뢰성 확보 방안

  • SBOM