search menu icon-carat-right cmu-wordmark

Software Transparency: Securing the Digital Supply Chain

Presentation
This session was presented by Chris Hughes at DevSecOps Days Washington, D.C., held virtually on October 12, 2022.
Publisher

Software Engineering Institute

Subjects

Abstract

In this session, I will discuss relevant events and emerging requirements of the software supply chain. I will be touching on topics such as SolarWinds, Log4j, the Cyber EO, SBOM's/VEX, SLSA, and more.

Chris Hughes is the CISO and Co-Founder of Aquia, a consulting firm focused on Cloud Security, Cyber, and DevSecOps in the public sector such as Federal Civilian and DoD agencies. He has nearly 20 years of experience in Cybersecurity. Chris also teaches as an adjunct professor in M.S. Cybersecurity programs at the University of Maryland Global Campus (UMGC) and Capitol Technology University. Chris is active in industry groups such as the Cloud Security Alliance (CSA) and Cloud Native Computing Foundation (CNCF). Chris regularly speaks, teaches, and consults around complex cloud security challenges facing the industry.