<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Software Supply Chain Attacks and the Need for Security on SK telecom Open Source</title><link>https://sktelecom.github.io/en/guide/supply-chain/overview/</link><description>Recent content in Software Supply Chain Attacks and the Need for Security on SK telecom Open Source</description><generator>Hugo</generator><language>en</language><atom:link href="https://sktelecom.github.io/en/guide/supply-chain/overview/index.xml" rel="self" type="application/rss+xml"/><item><title>Regulatory Trends</title><link>https://sktelecom.github.io/en/guide/supply-chain/overview/regulations/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://sktelecom.github.io/en/guide/supply-chain/overview/regulations/</guid><description>&lt;h2 id="1-united-states-executive-order-14028-eo-14028"&gt;1. United States: Executive Order 14028 (EO 14028)&lt;a class="td-heading-self-link" href="#1-united-states-executive-order-14028-eo-14028" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;In May 2021, the Biden administration issued the &amp;ldquo;Executive Order on Improving the Nation&amp;rsquo;s Cybersecurity (Executive Order 14028).&amp;rdquo; This was a decisive turning point at which supply chain security began to be addressed at the level of national security in the aftermath of the SolarWinds incident.&lt;/p&gt;
&lt;h3 id="key-provisions"&gt;Key Provisions&lt;a class="td-heading-self-link" href="#key-provisions" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Mandatory SBOM submission: Companies that supply software to the federal government must submit an SBOM.&lt;/li&gt;
&lt;li&gt;NIST guideline compliance: Companies must comply with the Secure Software Development Framework (SSDF) defined by NIST (the U.S. National Institute of Standards and Technology).&lt;/li&gt;
&lt;li&gt;Minimum standards: The U.S. administration led standardization by defining the minimum elements of an SBOM (data fields, automation support, etc.).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="2-european-union-eu-cyber-resilience-act-cra"&gt;2. European Union (EU): Cyber Resilience Act (CRA)&lt;a class="td-heading-self-link" href="#2-european-union-eu-cyber-resilience-act-cra" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Through the Cyber Resilience Act (CRA), the EU has enacted into law security requirements spanning the entire lifecycle of digital products.&lt;/p&gt;</description></item><item><title>SK Telecom Supply Chain Security Policy</title><link>https://sktelecom.github.io/en/guide/supply-chain/overview/policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://sktelecom.github.io/en/guide/supply-chain/overview/policy/</guid><description>&lt;blockquote&gt;
&lt;hr&gt;
&lt;p&gt;NOTICE.&lt;/p&gt;
&lt;p&gt;In accordance with internal security and document management policies, this document is a summary that excludes confidential content. Please note that it is written around high-level key points rather than the full content.&lt;/p&gt;
&lt;hr&gt;
&lt;/blockquote&gt;
&lt;h2 id="1-purpose-of-the-policy"&gt;1. Purpose of the Policy&lt;a class="td-heading-self-link" href="#1-purpose-of-the-policy" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The purpose of this policy is to ensure the transparency of all software that SK Telecom adopts, and to identify and eliminate, in advance, the risks of known vulnerabilities and license violations.&lt;/p&gt;</description></item></channel></rss>