Croot Blog

Home About Tech Hobby Archive

⚠️

이 블로그의 모든 포스트는 Notion 데이터베이스를 자동 변환하여 작성 되었습니다.
따라서 문서에 따라 깨져 보일 수 있습니다.
더 많은 내용이 궁금하시다면 👀 Notion 보러가기

SW 공급망 보안 가이드라인

[240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf](https://prod-files-secure.s3.us-west-2.amazonaws.com/8daffe33-d95b-4c96-91e6-1b899bcdb2d7/0f5f0886-db60-4a61-8e90-912aeea997fd/240513-%28%EC%9A%94%EC%95%BD%EB%B3%B8%29_SW%EA%B3%B5%EA%B8%89%EB%A7%9D_%EB%B3%B4%EC%95%88_%EA%B0%80%EC%9D%B4%EB%93%9C%EB%9D%BC%EC%9D%B8.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIAZI2LB4665KQVTIAC%2F20260520%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260520T045651Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEBwaCXVzLXdlc3QtMiJHMEUCIFUuGPFNJ4JDQKb4OCUTU2rCRbAGL2eNj%2BaAYkJ6j9jrAiEAqTZEwl2z3VAB297fRyDc1hrkXrvCuKIAt%2F4vojwKegAqiAQI5f%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARAAGgw2Mzc0MjMxODM4MDUiDKUEhvFf5L5HDy%2BfACrcA6yrJ33I5fgkZf8B9xiuIPTDWHbTGl1wqjYWMLp4SaXyj8LhSlq%2FxAuDwMMDrG5TG2k7t6lVlxlxBHKWR7Qy6Zl%2B6fQJbHwQ8gEUbE1s4DJ2ciWcUkfD%2Fknmr86JWwRwspYsYhE0lq7A640FSV1314xCbGn%2FRwGVrRjmmsGLmyfqLqom5xiScGgcQwzE9edOJZYIKeBziNb12G0R9ikFp4%2FimGhcYHrMOjoWOzJcIUmSm%2B1%2B2eyItuOX29SGPd2yb%2FUW7%2BhdyYenyJpiymNsIEifRge46yu4ZIc1aDFkD1dLPDKoCLWojOHSD0LlVSwe0Q5FoSSID0XuyTDlk4nmrFoN8XhV6PWXICDH%2BnMUngSEJEQwD89F9Uga9JE8sAdskMeaGw9UrkXTkv4m5sdRe5v4zFJkZfvU4dNxNuobVilMrQKVqre%2F1TiKeZvc3%2F5r6ZlRA20GXJpMvrIkbHjdmYgsx%2Bs1Bvw9cpA2d4gYxiOgAcKCSRRPy1KiQEZhmwBfOTF9JVhdCh3dbP3TBsQg8mjUMOHWes%2FHFHJF2Cl9aFSvPwostuwwj6TV57Yh7zT0DnzFjJNEkSXhCz57SKqgnZ66kyT4sM6YS9XAMdUguSrgyoCG4Va6zT9DoNUSMMnctNAGOqUB%2B7eojElR69V%2F9%2BCpMXRq1DiYTyeJ5epLx8DIAbzAlXMlujmiA9FrfKd4ny5v5MYXldTJE8%2FdvfhbjVd16WfgeA%2B3NAUbagyde4rbM1xomSWvCiibme75aCZ2e7TB0KuyKGZw2itJVm5aoIfyncRqKotKGAUqNyNZd71qG96zJUnX1IPW%2BjkOHiSWe49I6YipaoAAUyxYhqI5ZVyuGOhRo%2F4yBQ%2Bq&X-Amz-Signature=2e83e2d03bfa6624acaecfc6619cdacfc70e05ed3d829f2c56cf566837a8012a&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

C-SCRM

  1. 전사 : 상위 수준의 전략, 실행계획 및 정책
  2. 프로세스 : 하위 수준의 전략, 실행계획 및 정책
  3. 운영 : 계획

구축방안

  • SSDF

신뢰성 확보 방안

  • SBOM