Supply Chain Security

According to security education company Practical DevSecOps, software supply chain vulnerabilities are weaknesses that can be exploited within the network of dependencies that make up a software product.⁠1 These dependencies include third-party libraries, open-source code, development tools, and AI models. If any component in this chain is compromised, it can introduce risks across the entire software system, potentially resulting in data breaches, unauthorized access, or corrupted outputs. The purpose of this control is to vet all integrated tools, plugins, retrievers, and dependencies for integrity and update control, thereby preventing backdoors or unsafe interactions through untrusted dependencies or third-party APIs.

To mitigate software supply chain security risks, Practical DevSecOps, OWASP, and penetration testing company Breachlock recommend the following best practices⁠2

  • Inventory all software components and their origins
  • Apply least privilege access control
  • Leverage automated security tools in your Continuous Integration/Continuous Delivery (CI/CD) pipeline to evaluate and uphold the integrity of supply chain components
  • Continuously monitor software components and reassess their security status to maintain compliance and prevent breaches
  • Cryptographically sign serialized software and third-party vendor components to protect against unauthorized changes
  • Use only trusted suppliers and regularly review their terms of service and privacy policies
  • Maintain a software bill of materials (SBOM) to track all dependencies and their vulnerabilities
  • Use AI red‑teaming to evaluate third-party models, focusing on anomaly detection and adversarial robustness
  • Patch vulnerabilities as soon as possible and mitigate risks from outdated components.

Commercial Off-the-Shelf Solutions and Simple Recommendations

How Does This Relate to the Rest of the Guide or Other Threats That the User Cares About?

  • Supply chain: A.CCPC-2, A.CM-1, A.CPCC-3, A.CSM-1, A.DIV-1, A.DIV-2, A.DSAP-1, A.DSAP-2, A.ISCM-1, A.MSAT-1, A.PS-1, A.PS-2, A.VM-1, CC.ACA-2, CC.CM-1, CC.ISM-1, CC.NSI-1, CC.PSC-1, CC.SI-1, CC.CSM-1, CC.TES-1, COP.ACA-1, COP.ACA-3, COP.ACA-4, COP.CM-1, COP.DRCC-2, COP.ISM-1, COP.NSI-2, COP.CSM-1, D.ACA-1, D.ACA-2, D.CSM-1, D.DBR-1, D.DIS-1, D.DQIA-1, D.DQIA-3, D.DST-2, D.NSI-1, D.PPT-1, D.RDTP-2, D.TPS-1, E.CSM-1, E.ISCM-1, E.NSC-1, E.QA-1, HT.ACA-3, HT.CIS-1, HT.CRT-1, HT.DH-1, HT.DH-2, HT.HOAC-1, HT.IRA-1, HT.ISMG-1, HT.PSAM-1, HT.PSAM-2, HT.PSBV-1, HT.RBA-1, HT.RBA-2, HT.RBA-3, HT.STAP-1, HT.STAP-2, HT.STAP-4, IE.ACA-1, IE.ISCM-1, IE.ISCM-2, IE.MLCM-1, IE.MLCM-2, IE.NSAP-1, IE.NSAP-2, IE.SAVM-2, IE.TPS-1, IE.TPS-2, II.ISCM-1, II.ISCM-2, II.NSS-1, II.OSCM-1, II.OSCM-2, II.SAVM-2, MT.ACG-1, MT.ISM-1, MT.ISM-2, MT.MPAT-1, MT.MPAT-2, MT.SCPS-1, MT.SCPS-2, MT.TES-1, MT.TES-2, MW.ACA-1, MW.ACA-2, MW.BR-1, MW.CPMW-1, MW.CPMW-2, MW.CPMW-3, MW.DIDV-2, MW.ISM-1, MW.ISM-2, MW.NSC-2, MW.PSC-1, MW.PSC-2, MW.SSI-1, MW.SSI-2, MW.VM-1, MW.VM-2
  • OWASP:
    • LLM05: Supply Chain Vulnerabilities
    • LLM07: Insecure Plugin Design
    • LLM08: Excessive Agency
    • LLM10: Supply Chain Vulnerabilities
    • ML06: AI Supply Chain Attack

Other Sources of Information About This Topic

  • “Software Supply Chain with Zero Trust” (Practical DevSecOps)⁠23
  • “Software Supply Chain Vulnerabilities in Large Language Models (LLMs)” (Practical DevSecOps)⁠24
  • “Evaluating and Mitigating Software Supply Chain Security Risks” (Practical DevSecOps)⁠25
  • “Security Planning for LLM‑Based Applications” (Microsoft)⁠26
  • “Integrating Security into CI/CD Pipelines” (Microsoft Reactor)⁠27
  • “Open LLM Security Risks and Best Practices” (EPAM Systems)⁠28
  • “CI/CD Security” (Spacelift)⁠29
  • “Top 10 CI/CD Security Tools” (Spectral)⁠30
  • “10 Best AI Security Tools for LLM and GenAI Application Protection” (Mindgard)⁠31
  • “CISO Guide” (Breachlock)⁠32
  • “OWASP Top 10 LLM Updated 2025” (Oligo)⁠33

Notes

  1. Practical DevSecOps, Safeguarding Supply Chains in the Digital Era. Return to content
  2. Kumar, “7 Pillars to Strengthen Software Supply Chain Security”; OWASP, “Software Supply Chain Security”; BreachLock, “Key Findings from BreachLock Pentesting Intelligence Report 2023.” Return to content
  3. Mindgard, “Homepage.” Return to content
  4. AWS, “Amazon Bedrock Guardrails.” Return to content
  5. Holistic AI, “Homepage.” Return to content
  6. Adversarial Robustness Toolbox, “Homepage.” Return to content
  7. NVIDIA Developer, “NVIDIA Flare.” Return to content
  8. Flower Labs, “Homepage.” Return to content
  9. Netskope, “Securing AI.” Return to content
  10. Nightfall, “Safeguard Sensitive Data Across the AI Stack.” Return to content
  11. Cyberhaven, “Cyberhaven for Generative AI.” Return to content
  12. Symmetry Systems, “Symmetry Modern Data Security Platform.” Return to content
  13. Black Duck (by Synopsys), “Homepage.” Return to content
  14. Spectral, “Homepage.” Return to content
  15. Appknox, “Homepage.” Return to content
  16. Jit, “Homepage.” Return to content
  17. Tenable, “Tenable One.” Return to content
  18. Check Point, “CloudGuard.” Return to content
  19. Aqua Security, “Automate DevSecOps.” Return to content
  20. PortSwigger (Burp Suite), “What Do You Want to Do.” Return to content
  21. Checkmarx, “Homepage.” Return to content
  22. SonarSource, “SonarQube.” Return to content
  23. Kumar, “Software Supply Chain with Zero Trust.” Return to content
  24. Kumar, “Software Supply Chain Vulnerabilities in Large Language Models (LLMs).” Return to content
  25. Kumar, “Evaluating and Mitigating Software Supply Chain Security Risks.” Return to content
  26. Microsoft, “Security Planning for LLM‑Based Applications.” Return to content
  27. Beer and Jozwiak, “Integrating Security into CI/CD Pipelines.” Return to content
  28. Broniowski and Nurzhanov, “Open LLM Security Risks and Best Practices.” Return to content
  29. Birade, “CI/CD Security.” Return to content
  30. Katz, “Top 10 CI/CD Security Tools.” Return to content
  31. Glynn, “10 Best AI Security Tools for LLM and GenAI Application Protection (2025).” Return to content
  32. BreachLock, “CISO Guide.” Return to content
  33. Lumelsky, “OWASP Top 10 LLM, Updated 2025.” Return to content