Securing Your IT Supply Chain: Key Insights and Strategies

IT Supply Chain: Will Yours Be Compromised?

October 29, 2012
By Derek Weeks

4 minute read time

Gartner recently published research about the enterprise IT supply chain and impending threats that should encourage organizations to act. An overview of the research is available on Help Net Security: "Enterprise IT supply chains will be compromised." The title sounds ominous, but it's a good read that advises organizations to take a holistic approach to protecting the IT supply chain. We were happy to see that Neil MacDonald and Ray Valdes from Gartner cite research Sonatype did with Aspect Security; research on open source software (OSS) downloads and how component vulnerability can impact the health of the IT supply chain.

Gartner's take is in line with how Sonatype sees the world. In the remainder of this post, we'll address aspects that are particularly interesting and offer initial considerations about how to optimize the IT supply chain.

The New Reality

Some Initial Recommendations

We'll continue to cover this topic in future blog posts, but here are some initial recommendations or considerations for securing the software aspect of your IT supply chain:

Stay tuned as we explore and continue to explore the concept of an IT supply chain.

Written by Derek Weeks
Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.