Problem Statement
How would you vet a third-party software supplier for supply chain risk?
Explanation
Ask for an S B O M and vulnerability status. Review their build and signing process, including provenance and who can push releases. Check policy for reporting and fixing vulnerabilities. Map their controls to SSDF or SCVS so you have a common language. Finally, test updates in a sandbox and monitor behavior. This shows you can turn policy into real checks.
Code Solution
SolutionRead Only
Checklist: SBOM → signing & provenance → vuln SLA → access control → incident comms → pilot test
