55
66# OWASP Software Component Verification Standard
77
8- The Software Component Verification Standard (SCVS) is a community-driven effort to establish a framework for
9- identifying activities, controls, and best practices, which can help in identifying and reducing risk in a software
10- supply chain.
8+ The Software Component Verification Standard (SCVS) is a community-driven effort to
9+ establish a framework for identifying activities, controls, and best practices, which can help in identifying and
10+ reducing risk in a software supply chain.
1111
1212Managing risk in the software supply chain is important to reduce the surface area of systems vulnerable to exploits,
1313and to measure technical debt as a barrier to remediation.
1414
15- Measuring and improving software supply chain assurance is crucial for success. Organizations with supply chain
16- visibility can protect their brand, increase trust, reduce time-to-market, and impact costs in the event of a
17- supply chain incident.
15+ Measuring and improving software supply chain assurance is crucial for success. Organizations with supply chain visibility
16+ are better equipped to protect their brand, increase trust, reduce time-to-market, and manage costs in the event of a
17+ supply chain incident.
1818
1919Software supply chains involve:
2020 - technology
@@ -23,7 +23,7 @@ Software supply chains involve:
2323 - institutions
2424 - and additional variables
2525
26- It is important to acknowledge that raising the bar for supply chain assurance requires the active participation of
26+ Raising the bar for supply chain assurance requires the active participation of
2727risk managers, mission owners, and business units like legal and procurement, which have not traditionally been involved
2828with technical implementation.
2929
@@ -33,10 +33,10 @@ exposure, regulatory requirements, and constrained financial and human resources
3333unachievable, or that bring development or procurement to a standstill, constitute their own security and institutional
3434risks.
3535
36- SCVS is designed to be implemented incrementally, and to allow organizations to phase in controls at different levels
37- over time.
36+ SCVS is designed to be implemented incrementally, and to allow organizations to
37+ phase in controls at different levels over time.
3838
3939### SCVS has the following goals:
4040
4141* Develop a common set of activities, controls, and best-practices that can reduce risk in a software supply chain
42- * Devise a path to baseline and mature software supply chain vigilance
42+ * Identify a baseline and path to mature software supply chain vigilance
0 commit comments