Using CNCF Best Practices to Enhance Software Supply Chain Security
CNCF [Cloud Native Computing Foundation] via YouTube
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Learn Generative AI, Prompt Engineering, and LLMs for Free
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This presentation describes how 3M used CNCF best practices to improve security across its software development lifecycle, with emphasis on open-source components and preparing for supply chain attacks and vulnerabilities such as Log4j. It also discusses the organization’s progress toward a standards-based software bill of materials.
Syllabus
Intro
Ryan Gibbons 3M
Software Supply Chain
How This Worked at 3M
Where Did We Start
Before and After
DevSecops
Joe Bidens Executive Cyber Security Order
The CNCF Document
What is it about
The document
Conors approach
Dynamic Inventory
Lessons Learned
Taught by
CNCF [Cloud Native Computing Foundation]