Talk With an Expert

Prescriptive Model for Software Supply Chain Assurance in Private Cloud Environments

Prescriptive Model for Software Supply Chain Assurance in Private Cloud Environments (PDF, 3.73MB)Published: 14 Oct, 2020
Created by:
Robert Wood

As companies embrace Continuous Integration/Continuous Deployment (CI/CD) environments, automated controls are critical for safeguarding the Software Development Life Cycle (SDLC). The ability to vet and whitelist container images before installation is vitally important to ensuring the security of corporate networks. Google Cloud offers the Container Registry in combination with Binary Authorization to understand the container footprint in the environment and provide a mechanism for enforcing policies. Grafeas and Kritis are open-source alternatives. This paper evaluates Grafeas and Kritis and provides specific recommendations for using these tools or equivalents in private cloud environments.