Securing the Software Supply Chain: CISA Best Practices

Cookiebot by Usercentrics - opens in a new window

This website uses cookies

We use cookies to understand how you use our site and to improve your experience. This includes personalizing content and advertising with the use of third-party business partners. To learn more, [click here](/content/privacy-policy ""/index.html).

[#GPC_BANNER_ICON#]

[#GPC_TOAST_TEXT#]

Consent Selection

Necessary

Preferences

Statistics

Marketing

Show details

Details

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

cookies.js Determines whether the visitor has accepted the cookie consent box. This ensures that the cookie consent box will not be presented again upon re-entry.

Maximum Storage Duration: SessionType: HTTP Cookie

sp_window_session Maintains the session for the embedded Spotify player to ensure it functions correctly during the current visit.

Maximum Storage Duration: SessionType: HTTP Cookie

__Host-device_id Used by Spotify to identify the user’s device and enable secure authentication and playback of embedded Spotify content.

Maximum Storage Duration: SessionType: HTTP Cookie

anchor-website#local-forage-detect-blob-support Detects browser storage capabilities required for embedded Spotify podcast playback.

Maximum Storage Duration: PersistentType: IndexedDB

ES||STORAGE_ID Stores a technical identifier required to manage local storage for embedded Spotify podcast playback.

Maximum Storage Duration: PersistentType: HTML Local Storage

ES|s4p-hosted|STORAGE_ID Stores a technical identifier required to manage local storage for embedded Spotify podcast playback.

Maximum Storage Duration: PersistentType: HTML Local Storage

ga_clientId Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration: PersistentType: HTML Local Storage

ak_bmsc This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

Maximum Storage Duration: 1 dayType: HTTP Cookie

f5avraaaaaaaaaaaaaaaa_session_ Registers the website's speed and performance. This function can be used in context with statistics and load-balancing.

Maximum Storage Duration: SessionType: HTTP Cookie

JSESSIONID Preserves users states across page requests.

Maximum Storage Duration: SessionType: HTTP Cookie

CookieConsent Stores the user's cookie consent state for the current domain

Maximum Storage Duration: 1 yearType: HTTP Cookie

_gh_sess Preserves users states across page requests.

Maximum Storage Duration: SessionType: HTTP Cookie

logged_in Registers whether the user is logged in. This allows the website owner to make parts of the website inaccessible, based on the user's log-in status.

Maximum Storage Duration: 1 yearType: HTTP Cookie

Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.

_ga [x3] Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration: 2 yearsType: HTTP Cookie

_gid [x2] Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration: 1 dayType: HTTP Cookie

_GRECAPTCHA This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

Maximum Storage Duration: 180 daysType: HTTP Cookie

rc::a This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

Maximum Storage Duration: PersistentType: HTML Local Storage

rc::b This cookie is used to distinguish between humans and bots.

Maximum Storage Duration: SessionType: HTML Local Storage

rc::c This cookie is used to distinguish between humans and bots.

Maximum Storage Duration: SessionType: HTML Local Storage

rc::f This cookie is used to distinguish between humans and bots.

Maximum Storage Duration: PersistentType: HTML Local Storage

__hs_do_not_track Stores the user's cookie consent state for the current domain

Maximum Storage Duration: 180 daysType: HTTP Cookie

cookietest This cookie is used to determine if the visitor has accepted the cookie consent box.

Maximum Storage Duration: SessionType: HTTP Cookie

bcookie Used in order to detect spam and improve the website's security.

Maximum Storage Duration: 1 yearType: HTTP Cookie

li_gc Stores the user's cookie consent state for the current domain

Maximum Storage Duration: 180 daysType: HTTP Cookie

_vwo_consent Stores the user’s cookie consent preferences for VWO to ensure that testing and tracking scripts are only executed in accordance with the user’s consent choices.

Maximum Storage Duration: SessionType: HTTP Cookie

datadome Used in context with the website's BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website.

Maximum Storage Duration: SessionType: HTTP Cookie

__cflb [x2] Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.

Maximum Storage Duration: 1 dayType: HTTP Cookie

#.#-#-#-#-#.ack Used to contain user’s survey and quiz answers in Local Storage.

Maximum Storage Duration: PersistentType: HTML Local Storage

#.#-#-#-#-#.inProgress Used to contain user’s survey and quiz answers in Local Storage.

Maximum Storage Duration: PersistentType: HTML Local Storage

#.#-#-#-#-#.queue Used to contain user’s survey and quiz answers in Local Storage.

Maximum Storage Duration: PersistentType: HTML Local Storage

#.#-#-#-#-#.reclaimEnd Used to contain user’s survey and quiz answers in Local Storage.

Maximum Storage Duration: PersistentType: HTML Local Storage

#.#-#-#-#-#.reclaimStart Used to contain user’s survey and quiz answers in Local Storage.

Maximum Storage Duration: PersistentType: HTML Local Storage

test_rudder_cookie This cookie determines whether the browser accepts cookies.

Maximum Storage Duration: 1 yearType: HTTP Cookie

__cf_bm [x19] This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

Maximum Storage Duration: 1 dayType: HTTP Cookie

__q_state_f3KQDBMfpPYzsDQe Stores session state required for embedded Qualified chat functionality.

Maximum Storage Duration: 10 yearsType: HTTP Cookie

_cq_s CHEQ cookies are used to protect websites, applications, and online services from bots, automated abuse, fraud, and other invalid or malicious activity.

Maximum Storage Duration: 7 daysType: HTTP Cookie

_cq_session CHEQ cookies are used to protect websites, applications, and online services from bots, automated abuse, fraud, and other invalid or malicious activity.

Maximum Storage Duration: 2 yearsType: HTTP Cookie

_cq_suid This cookie is used to distinguish between humans and bots.

Maximum Storage Duration: SessionType: HTTP Cookie

_cq_check Determines whether the user has accepted the cookie consent box.

Maximum Storage Duration: SessionType: HTTP Cookie

cg_uuid Necessary for the website security.

Maximum Storage Duration: 11 monthsType: HTTP Cookie

sc_anonymous_id Used in context with the 3D-view-function on the website.

Maximum Storage Duration: 10 yearsType: HTTP Cookie

visitorId Preserves users states across page requests.

Maximum Storage Duration: 1 yearType: HTTP Cookie

_cfuvid [x2] This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.

Maximum Storage Duration: SessionType: HTTP Cookie

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

reduxPersist%3AlocalStorage Stores application state locally to ensure the proper functioning of embedded Spotify podcast playback.

Maximum Storage Duration: 7 daysType: HTTP Cookie

reduxPersist%3Atutorial Stores user interface state related to tutorial or guidance features for embedded Spotify podcast content.

Maximum Storage Duration: 7 daysType: HTTP Cookie

reduxPersistIndex Maintains website settings across multiple visits.

Maximum Storage Duration: 7 daysType: HTTP Cookie

anchor-website#keyvaluepairs Stores configuration and state information to enable and manage embedded Spotify podcast playback.

Maximum Storage Duration: PersistentType: IndexedDB

com.spotify.single.item.cache:anchor-public-website Caches podcast content data to enable reliable loading and playback of embedded Spotify episodes.

Maximum Storage Duration: PersistentType: HTML Local Storage

hubspot-modern-theme Stores the user's HubSpot interface theme preference to provide a consistent visual experience across sessions.

Maximum Storage Duration: PersistentType: HTML Local Storage

lidc Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.

Maximum Storage Duration: 1 dayType: HTTP Cookie

nv_visitor_consent Stores whether a visitor has already provided consent or identification information so they aren't repeatedly prompted. It supports the user experience rather than analytics or advertising. Navattic describes visitor cookies as enabling previously identified visitors to skip subsequent form fills when this optional feature is enabled.

Maximum Storage Duration: 180 daysType: HTTP Cookie

theme-ui-color-mode Remembers the user's preferences in terms of font size and colours on the website.

Maximum Storage Duration: PersistentType: HTML Local Storage

__q_local_form_debug Supports debugging and proper operation of embedded Qualified chat and form features.

Maximum Storage Duration: PersistentType: HTML Local Storage

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

sp_t Collects anonymized usage data to measure performance and interactions with embedded Spotify podcast content.

Maximum Storage Duration: SessionType: HTTP Cookie

ES||INSTALLATION_ID Assigns an installation identifier to support aggregated usage measurement for embedded Spotify podcast content.

Maximum Storage Duration: PersistentType: HTML Local Storage

ES|s4p-hosted|INSTALLATION_ID Assigns an installation identifier to support aggregated usage measurement for embedded Spotify podcast content.

Maximum Storage Duration: PersistentType: HTML Local Storage

_octo Pending

Maximum Storage Duration: 1 yearType: HTTP Cookie

Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.

_ga_# Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration: 2 yearsType: HTTP Cookie

__hssc Identifies if the cookie data needs to be updated in the visitor's browser.

Maximum Storage Duration: 1 dayType: HTTP Cookie

__hssrc Used to recognise the visitor's browser upon reentry on the website.

Maximum Storage Duration: SessionType: HTTP Cookie

__hstc Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.

Maximum Storage Duration: 180 daysType: HTTP Cookie

hubspotutk Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.

Maximum Storage Duration: 180 daysType: HTTP Cookie

hs-cta-interactions#cta Tracks interactions with call-to-action elements to measure engagement through HubSpot.

Maximum Storage Duration: PersistentType: IndexedDB

_vis_opt_exp_#_combi Used by Visual Website Optimizer to ensure that the same user interface variant is displayed for each visit, if the user is participating in a design experiment.

Maximum Storage Duration: 100 daysType: HTTP Cookie

number(#) Used to track user’s interaction with embedded content.

Maximum Storage Duration: SessionType: HTML Local Storage

analyze This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.

Maximum Storage Duration: SessionType: Pixel Tracker

collect/v.gif Pending

Maximum Storage Duration: SessionType: Pixel Tracker

l.gif This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.

Maximum Storage Duration: SessionType: Pixel Tracker

rl_anonymous_id Registers a unique ID for the visitor in order for the website to recognize the visitor upon re-entry.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_page_init_referring_domain Stores the domain of the website that originally referred the visitor. Used for analytics and attribution to understand how visitors arrive at the site and measure traffic sources.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_session Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.

Maximum Storage Duration: 1 yearType: HTTP Cookie

Zotahoma, geneva, sans-seriftahoma, geneva, sans-serifmozilla/5.0 (windows nt 10.0; win64; x64) applewebkit/537.36 (khtml, like gecko) chrome/141.0.7390.37 safari/537.36 Stores browser characteristics to support visitor identification and analytics, including browser and device attributes used to improve measurement and distinguish unique visitors.

Maximum Storage Duration: PersistentType: HTML Local Storage

nv_uid Assigns a pseudonymous identifier to measure engagement with interactive product walkthroughs via Navattic.

Maximum Storage Duration: 1 yearType: HTTP Cookie

__q_domainTest Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.

Maximum Storage Duration: SessionType: HTTP Cookie

tracker/tc_imp.gif Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.

Maximum Storage Duration: SessionType: Pixel Tracker

ziwsSession Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.

Maximum Storage Duration: SessionType: HTML Local Storage

ziwsSessionId Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.

Maximum Storage Duration: SessionType: HTML Local Storage

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

lastExternalReferrer Detects how the user reached the website by registering their last URL-address.

Maximum Storage Duration: PersistentType: HTML Local Storage

lastExternalReferrerTime Detects how the user reached the website by registering their last URL-address.

Maximum Storage Duration: PersistentType: HTML Local Storage

_fbp Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.

Maximum Storage Duration: 3 monthsType: HTTP Cookie

6suuid Registers user behaviour and navigation on the website, and any interaction with active campaigns. This is used for optimizing advertisement and for efficient retargeting.

Maximum Storage Duration: 400 daysType: HTTP Cookie

sp_tr Tracks user interactions across Spotify services to support advertising measurement and campaign attribution.

Maximum Storage Duration: SessionType: HTTP Cookie

Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.

IDE Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

Maximum Storage Duration: 400 daysType: HTTP Cookie

test_cookie Pending

Maximum Storage Duration: 1 dayType: HTTP Cookie

pagead/1p-conversion/#/ Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.

Maximum Storage Duration: SessionType: Pixel Tracker

pagead/1p-user-list/# Tracks if the user has shown interest in specific products or events across multiple websites and detects how the user navigates between sites. This is used for measurement of advertisement efforts and facilitates payment of referral-fees between websites.

Maximum Storage Duration: SessionType: Pixel Tracker

_gcl_au Used to measure the efficiency of the website’s advertisement efforts, by collecting data on the conversion rate of the website’s ads across multiple websites.

Maximum Storage Duration: 3 monthsType: HTTP Cookie

_gcl_ls Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.

Maximum Storage Duration: PersistentType: HTML Local Storage

__hmpl Collects information on user preferences and/or interaction with web-campaign content - This is used on CRM-campaign-platform used by website owners for promoting events or products.

Maximum Storage Duration: SessionType: HTML Local Storage

__ptq.gif Sends data to the marketing platform Hubspot about the visitor's device and behaviour. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration: SessionType: Pixel Tracker

HUBLYTICS_EVENTS_53 [x2] Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement.

Maximum Storage Duration: SessionType: HTML Local Storage

_uetsid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: PersistentType: HTML Local Storage

_uetsid_exp Contains the expiry-date for the cookie with corresponding name.

Maximum Storage Duration: PersistentType: HTML Local Storage

_uetvid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: PersistentType: HTML Local Storage

_uetvid_exp Contains the expiry-date for the cookie with corresponding name.

Maximum Storage Duration: PersistentType: HTML Local Storage

MR Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: 7 daysType: HTTP Cookie

MUID Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains.

Maximum Storage Duration: 1 yearType: HTTP Cookie

_uetsid Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement.

Maximum Storage Duration: 1 dayType: HTTP Cookie

_uetvid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rp.gif Necessary for the implementation of the Reddit.com's share-button function.

Maximum Storage Duration: SessionType: Pixel Tracker

_rdt_uuid [x2] Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: 3 monthsType: HTTP Cookie

_vis_opt_s Used by Visual Website Optimizer to determine if the visitor is participating in a design experiment.

Maximum Storage Duration: 100 daysType: HTTP Cookie

_vis_opt_test_cookie Used to check if the user's browser supports cookies.

Maximum Storage Duration: SessionType: HTTP Cookie

_vwo_ds Collects data on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded with the purpose of generating reports for optimising the website content.

Maximum Storage Duration: 2 monthsType: HTTP Cookie

_vwo_sn Collects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.

Maximum Storage Duration: 1 dayType: HTTP Cookie

_vwo_uuid Used by Visual Website Optimizer to ensure that the same user interface variant is displayed for each visit, if the user is participating in a design experiment.

Maximum Storage Duration: 1 yearType: HTTP Cookie

_vwo_uuid_v2 This cookie is set to make split-tests on the website, which optimizes the website's relevance towards the visitor – the cookie can also be set to improve the visitor's experience on a website.

Maximum Storage Duration: 1 yearType: HTTP Cookie

_vwo_584728_config Stores configuration settings for VWO to support website analytics and optimization testing.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_eventHist Stores visitor event history data used by VWO for analytics, A/B testing, and website optimization.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_eventHistLastSession Used by VWO to retain event interaction history from the user’s last browsing session to support analytics and experiment continuity.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_eventHistSession Used by VWO to track visitor interactions and experiment events within a browsing session.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_nls_q_# Collects data on user interactions to support website analytics and optimization testing through VWO.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_nlsCache Stores cached visitor session and optimization data used by VWO to improve experiment performance and reduce repeated data processing.

Maximum Storage Duration: PersistentType: HTML Local Storage

_vwo_visProps Used by VWO to retain visitor attributes and properties for analytics, A/B testing, and experiment targeting purposes.

Maximum Storage Duration: PersistentType: HTML Local Storage

vwoSn This cookie is set to make split-tests on the website, which optimizes the website's relevance towards the visitor – the cookie can also be set to improve the visitor's experience on a website.

Maximum Storage Duration: PersistentType: HTML Local Storage

dd_testcookie Pending

Maximum Storage Duration: SessionType: HTTP Cookie

ddSession_datadome Pending

Maximum Storage Duration: PersistentType: HTML Local Storage

a/gif.gif Used by Informa TechTarget to measure interactions with marketing content, identify website visitors, and support campaign attribution and lead generation.

Maximum Storage Duration: SessionType: Pixel Tracker

i/jot/embeds Used by X (formerly Twitter) to support embedded content and to measure and personalize advertising and user interactions across websites.

Maximum Storage Duration: SessionType: Pixel Tracker

s.gif Registers user behaviour and navigation on the website, and any interaction with active campaigns. This is used for optimizing advertisement and for efficient retargeting.

Maximum Storage Duration: SessionType: Pixel Tracker

vwo_apm_sent Used by VWO to manage application performance monitoring and prevent duplicate performance data submissions.

Maximum Storage Duration: PersistentType: HTML Local Storage

__tld__ Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.

Maximum Storage Duration: SessionType: HTTP Cookie

rl_group_id Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_group_trait Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_page_init_referrer Registers how the user has reached the website to enable pay-out of referral commission fees to partners.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_trait Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.

Maximum Storage Duration: 1 yearType: HTTP Cookie

rl_user_id Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.

Maximum Storage Duration: 1 yearType: HTTP Cookie

v1/beacon/img.gif Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.

Maximum Storage Duration: SessionType: Pixel Tracker

_6senseCompanyDetails Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.

Maximum Storage Duration: PersistentType: HTML Local Storage

_an_uid Presents the user with relevant content and advertisement. The service is provided by third-party advertisement hubs, which facilitate real-time bidding for advertisers.

Maximum Storage Duration: 7 daysType: HTTP Cookie

_gd_session Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Maximum Storage Duration: 1 dayType: HTTP Cookie

_gd_svisitor Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Maximum Storage Duration: 2 yearsType: HTTP Cookie

_gd_visitor Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Maximum Storage Duration: 2 yearsType: HTTP Cookie

_cq_tuid Collects data on visitors. This information is used to assign visitors into segments, making website advertisement more efficient.

Maximum Storage Duration: SessionType: HTML Local Storage

_cq_duid Used by the website to protect against fraud in relation to its referral system.

Maximum Storage Duration: 3 monthsType: HTTP Cookie

Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.

Cross-domain consent[#BULK_CONSENT_DOMAINS_COUNT#]

[#BULK_CONSENT_TITLE#]

List of domains your consent applies to: [#BULK_CONSENT_DOMAINS#]

Cookie declaration last updated on 7/20/26 by Cookiebot

[#IABV2_TITLE#]

[#IABV2_BODY_INTRO#]

[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]

[#IABV2_BODY_PREFERENCE_INTRO#]

[#IABV2_LABEL_PURPOSES#]

[#IABV2_BODY_PURPOSES_INTRO#]

[#IABV2_BODY_PURPOSES#]

[#IABV2_LABEL_FEATURES#]

[#IABV2_BODY_FEATURES_INTRO#]

[#IABV2_BODY_FEATURES#]

[#IABV2_LABEL_PARTNERS#]

[#IABV2_BODY_PARTNERS_INTRO#]

[#IABV2_BODY_PARTNERS#]

About

Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our [Privacy Policy](/content/privacy-policy ""/index.html).

Do not sell or share my personal information

Allow allCustomize

Allow selectionReject Cookies

Arming the Defender Force and Securing the Software Supply Chain: Helping Developers Implement CISA Best Practices - Part 1

September 19, 2022 By Eric Hill

5 minute read time

I often refer to civilian DevSecOps practitioners working on critical infrastructure programs as the "Defender Force." We live in an era where they are more important than ever. Through critical infrastructure, the Homeland has become vulnerable to cyber attacks from our adversaries. For those unfamiliar with critical infrastructure, the Cybersecurity and Information Agency (CISA) defines 16 critical infrastructure sectors which are overwhelmingly privately owned in the USA.

As of late, these exact same adversaries have been targeting the software supply chain. This means it's now critical for DevSecOps practitioners of all roles and skill levels to have access to relevant knowledge and guidance to provide the best levels of protection possible.

However, even the highest levels of knowledge and guidance are useless without the platforms necessary to put those skills to use as nation-states and syndicates continue mounting offensive operations.

Enter Sonatype

At Sonatype, we provide a platform that serves as a force multiplier to the Defender Force, securing the software supply chain. Capabilities available in the Sonatype Platform include:

In August 2022, the Cybersecurity and Information Security Agency (CISA), the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA) released "Securing the Software Supply Chain: Recommended Practices Guide for Developers." This document acts as an extension of CISA's work in support of Executive Order 14028.

In Part 1 of this series, we will walk through the diagram labeled figure 3, found on page 15 of the original document, and explain in more detail how Sonatype Platform helps avert these attempts to undermine the security of the software supply chain. We will define the capabilities in use cases, corresponding to the numbers from the diagram in purple.

Diagram shared via Securing the Software Supply Chain: Recommended Practices Guide for Developers

Use Case #1

The situation:

A developer has been perusing the npm public open source repository and notices a new open source component that may be useful in a project. In the developer's Visual Studio Code IDE, which is configured with the Sonatype Lifecycle plug-in, they type in the commands to download the component. (1)

How Sonatype makes the process more secure: The component gets downloaded to the Sonatype Nexus Repository proxy repo from the npm public open source repository. The Sonatype Firewall AI/ML then flags the component as "suspicious" and places it in "quarantine" in the proxy repo. The developer then receives a message that the component has been placed in quarantine. (2)(3)

Next, Sonatype security analysts inspect the component and find that it is "malicious" and marks it as so in the data model. This means that the policy engine will now automatically quarantine the component if any other developers attempt to download the component in a separate environment.

Use Case #2

The situation: A developer decides to download a Java OSS component from the public Maven repository using the IntelliJ developer IDE, typing the relevant command in the environment. The OSS component does not violate any security policy configured in Sonatype Firewall and slips past to be downloaded to the Sonatype Nexus Repository proxy repo for use. The Java OSS component is then downloaded from the repo to the developer's filesystem, with the message forwarded as a response to the initial command. (1) (2) (3) (4) (5a)

How Sonatype increases security: In the IDE, the developer is able to view the SBOM of the current project by using the Sonatype Lifecycle plug-in. By clicking on the component, the developer can view the current vulnerability (CVE) posture of the OSS component that was downloaded. (4)

The developer’s branch is merged with the main branch. The nightly build breaks per the Sonatype Lifecycle Jenkins plug-in, flagging a policy violation due to a critical CVE recently reported on the OSS component. Stakeholders are messaged as configured and can navigate to the Sonatype Lifecycle Component Detail View for situational awareness of License, Security, Quality posture, and version update advice. (4) (5b)

Use Case #3

The situation: A release candidate is built into an OCI-compliant container destined for Kubernetes and placed into a Sonatype Nexus Repository staging repo. Security gate tests pass, and the Jenkins plug-in ensures that the SBOM–the results of the scan of the release candidate – is viewable in Sonatype Lifecycle. (4)

How Sonatype helps ensure greater security: All automated testing passes in the release phase, and a release package is built. The security gate checks also pass here, including a scan for SBOM via Sonatype Lifecycle. Next, the release package is placed in the Sonatype Nexus Repository release repo. Sonatype Lifecycle Continuous Monitoring is turned on to provide daily status updates on the SBOM regarding security, license, and quality violations.

On day 4, stakeholders are notified of a new critical CVE reported per a security policy violation. They are able to cut over to the server directly through their notifications to view the SBOM and gain situational awareness on License, Security, Quality posture, and version update advice per OSS component.

Securing the Software Supply Chain Is Hard Work

We hope that this series of blog posts will help DevSecOps practitioners defend critical infrastructure and help their executives understand how to operationalize the US government’s recommendations articulated in the "Secure Repository Process Flow" diagram above. However, these posts are not just for DevSecOps practitioners. We also hope to aid those involved with government policy.

In future additions to this series, we will continue to present the Sonatype Platform force multiplier in the context of US government policy and legislation. We have every intention to help arm the Defender Force with the capability to quickly and continuously harden our critical infrastructure as our adversaries are quickly taking advantage of our currently lagging cyber posture.

Written by Eric Hill

Eric Hill has a BS in Computer Engineering from the University of New Hampshire. His technical career spans nearly 3 decades. He has been involved with product development life cycle of telecommunications equipment and the advanced software that manages it. For nearly a decade he consulted in automation efforts on critical infrastructure. Mr. Hill is a DIB SME and has worked on numerous “dual use technology” efforts over the years. Today he is a Trusted Technical Advisor for Sonatype’s defense sector & federal customer base where he endeavors to provide industry thought leadership with a national security focus. Eric is married with three children and enjoys attending church, participating in cultural events and travelling with them. He volunteers his time to teach youth cultural Greek martial art. ...read more read less

Tags

secure software supply chainCybersecuritySonatype PlatformCISA best practicesSonatype LifecycleSonatype FirewallSonatype Nexus Repository

Related Resources

Blog Post

[The Hidden National Security Threat Inside AI-Driven Software](/content/blog/the-hidden-national-security-threat-inside-ai-driven-software "Internal link to The Hidden National Security Threat Inside AI-Driven Software blog post"/index.html)

Read More

Blog Post

[5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook](/content/blog/5-steps-to-turn-your-rmf-backlog-into-a-continuous-ato-the-csrmc-migration-playbook "Internal link to 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook blog post"/index.html)

Read More

Blog Post

[The Time Is Now to Prepare for CRA Enforcement](/content/blog/the-time-is-now-to-prepare-for-cra-enforcement "Internal link to The Time Is Now to Prepare for CRA Enforcement blog post"/index.html)

Read More

Twitter Widget Iframe