This page was machine-translated and may differ from the original. View original
With the US EO14028 deadline approaching, it's essential to strengthen software supply chain security.

▲The Zero Trust Supply Chain Security Policy Forum launch ceremony held by the Ministry of Science and ICT on October 26 (Photo: Ministry of Science and ICT)
All software compliance certifications required by September 2023
EO14028 has a significant impact on global software vendors.
EO14028 has a significant impact on global software vendors.
Last year, the U.S. government issued an executive order to “improve national cybersecurity” requiring the federal government to implement a zero-trust architecture. Accordingly, the deadline for compliance with this software EO is approaching as it is mandatory to submit a Software Bill of Materials (SBOM, a specification for identifying the components of the software) when supplying software-embedded products to US federal agencies.
Cloud-native security company Aqua Security (hereinafter referred to as Aqua) announced on the 21st that it is providing software supply chain security certification in compliance with U.S. Executive Order (EO) 14028.
This executive order from the U.S. government lists all software supply chain requirements that third-party software companies must meet or exceed to strengthen U.S. cybersecurity and protect the United States from malicious cyber actors.
Last September, the U.S. government released a guide titled "Enhancing the Security of the Software Supply Chain through Secure Software Development Practices," following EO 14028, outlining the effective dates by which agencies must ensure that software they have purchased or will purchase complies with the EO. By January 12, 2023, each agency's CIO must communicate the requirements to vendors, and by June 11 of that year, they must compile compliance certifications for critical software. After that, it is requiring that compliance certificates be collected for 'all' software by September 14th.
In Korea, too, at the 'Information Security Leaders' Night' event earlier this year, Chairman Lee Dong-beom of the Korea Information Security Industry Association (KISIA) emphasized, "We must pay attention to and follow the 'Executive Order on Cybersecurity (EO 14028)' issued by the Biden administration." On October 26, the Ministry of Science and ICT and the Korea Internet & Security Agency (President Lee Won-tae, hereinafter 'KISA') began responding to the US government's executive order by holding the 'Zero Trust and Supply Chain Security Forum Launch Ceremony' at the Boco Seoul Gangnam Hotel.
“This executive order has a profound impact on global software vendors,” said Dror Davidoff, CEO and co-founder of Aqua Security. “If you sell to the U.S. government or to companies that do business with the government, you will need to demonstrate compliance with this order.” He added, “As software supply chain attacks grow in sophistication and scale, the private sector must take proactive cybersecurity measures, and EO 14028 is a significant and bold step by the U.S. government to prevent cyber incidents.”
Aqua's Software Supply Chain Security is a comprehensive solution that provides protection across the entire software development lifecycle, helping software providers comply with and demonstrate compliance with EO requirements. Aqua emphasizes that it helps companies achieve compliance requirements within one month of deployment and includes reporting and management capabilities for initial and ongoing compliance verification.
Aqua Security stated that it ensures EO 14028 compliance by: △ensuring a secure configuration of the development environment through accompanying proofs; △proving that the source of the code is trustworthy and that code vulnerabilities have been fixed through accompanying proofs; △managing provenance data for internal and third-party code and securing SBOM for each released product; △maintaining a secure development process through accompanying proofs; and △maintaining data integrity and the provenance of open source software in use through accompanying proofs.
“Time is running out, and with only about 10 months left to comply with the mandate,” said Davidoff, adding that Aqua “not only makes it easier for software vendors to meet compliance requirements, but also gives them the confidence to prevent software supply chain attacks.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















