{"id":27376,"date":"2024-03-13T17:39:17","date_gmt":"2024-03-13T17:39:17","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/"},"modified":"2026-08-08T05:09:11","modified_gmt":"2026-08-08T05:09:11","slug":"three-tips-for-securing-the-federal-software-supply-chain","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","title":{"rendered":"Three tips for securing the federal software supply chain"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">If one were to delve beneath the surface and analyze the number one factor driving some of the most significant data breaches, legislation, and other technological trends in the federal space from the past year, one consistent thread would rise to the surface: the software supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite new legislation from the Biden Administration designed to protect the software supply chain, several government bodies fell victim to prominent supply chain attacks in 2023. Most notably, attackers exploited a vulnerability in the MOVEit Transfer software, which allowed them to infiltrate the software supply chain of thousands of companies without being detected. The Cybersecurity and Infrastructure Security Agency confirmed that several government agencies, banks, financial services companies, and universities were among the victims of the MOVEit Transfer software vulnerability that impacted over <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Ftechcrunch.com%2F2023%2F08%2F25%2Fmoveit-mass-hack-by-the-numbers%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936040495%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=Z%2Bofi%2BQ4Stpe4bn38iBQHdRDnF2ImS0paor41cmm7hw%3D&#038;reserved=0\">60 million people <\/a>worldwide.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the evolution of AI, machine learning, and large language models increasing at warp speed, developers are producing more software than ever before, and cyber adversaries continue to be on the lookout for their next victim. It is critical that federal agencies have the tools and processes in place to secure the software supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s where they should start:<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Tip #1: Prioritize Software Bill of Materials (SBOMs)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In 2024, the software landscape is poised for significant changes, with a growing emphasis on SBOMs &#8211; an essential tool for today\u2019s federal agencies. An SBOM provides increased transparency by disclosing software\u2019s components, whether built or bought, much like an ingredient list on food labels. Using an SBOM, federal organizations are able to precisely assess software components\u2019 risks and quickly address vulnerabilities \u2014 or simply pick a better software. President Biden\u2019s <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.whitehouse.gov%2Fbriefing-room%2Fpresidential-actions%2F2021%2F05%2F12%2Fexecutive-order-on-improving-the-nations-cybersecurity%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936047891%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=WECZJdcKyN3ndSBGQKwi6ntzLBBQorjhb%2F22rLQ%2FKzc%3D&#038;reserved=0\">Executive Order (E.O.) 14028<\/a> highlights the importance of SBOMs as a crucial way to drastically improve software supply chain security in response to growing cyber threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As concerns about supply chain attacks continue to escalate, compliance measures like E.O. 14028 will inevitably tighten, due to the increasing frequency and visibility of such large-scale cyber incidents. The proactive adoption of SBOMs is not only in response to heightened awareness, but will be the key differentiator in software maintenance and security. We suspect in this upcoming year that an increased emphasis will be placed on preventing and disclosing supply chain threats, similar to the <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.sec.gov%2Fnews%2Fstatement%2Fgerding-cybersecurity-disclosure-20231214%23%3A~%3Atext%3DTo%2520help%2520investors%2520evaluate%2520this%2Ccybersecurity%2520risk%2520management%252C%2520strategy%252C%2520and&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936056237%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=T%2FoTIQ%2BYqRrBjYVwsDOivu6wG8eIOYuuHqrVsskLQ14%3D&#038;reserved=0\">SEC\u2019s updated breach disclosure laws<\/a>, and similar compliance initiatives to be taken around the world.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Tip #2: Emphasize real-time visibility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The goal of preventing software supply chain attacks in the public sector will come from identifying software supply chain threats in real time before they unfold. That in itself is a challenge as the majority of these incidents\u2019 are near impossible to detect especially when so many software producers and consumers still cannot answer the question, \u201cwhat\u2019s in your software?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reason for the lack of knowledge? Chances are pretty high that federal organizations are relying on open-source software components \u2014 in fact, open source currently makes up approximately <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.linuxfoundation.org%2Fblog%2Fblog%2Fa-summary-of-census-ii-open-source-software-application-libraries-the-world-depends-on&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936064335%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=tgB%2FVrMti8xmrzOmIwXcrvdSKe7iaLX9bq95AdOearg%3D&#038;reserved=0\">70% to 90% of software today<\/a>. Despite its popularity, it doesn\u2019t come without risk. <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.lineaje.dev%2Freports&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936071468%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=SsaxCVbfRsbHyY2DFapV8SMP179IOciiIIMnSPUpMBg%3D&#038;reserved=0\">Lineaje research<\/a> from last year revealed that an overwhelming majority (82%) of open-source software components are susceptible to vulnerabilities, maintainability concerns, quality issues, or similar security problems. Some open-source components (a little over 5%) fail basic integrity checks \u2014 which might have prevented the compromises that led to the 3CX attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Real-time visibility into the quality of software components is going to be the difference between a well-maintained and secure software supply chain, and the next big software supply chain attack. It\u2019s critical that we address the danger landscape quicker than before in order to effectively secure the digital future.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Tip #3: Identify the lineage of AI<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the past year, organizations have increasingly focused on preventing cyberattacks targeting AI systems. This heightened attention is driven by the rising use and popularity of AI, enabling threat actors to exploit vulnerabilities in the software, particularly with open source models lacking sufficient guardrails. However, a crucial aspect is being overlooked. Many federal security teams are concentrating on defending against threats once AI is operational, fearing that threat actors might manipulate AI to influence engineering, IT, or security actions, potentially leading to compromises.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A frequently overlooked scenario in AI security is that security should start from the very beginning of building AI systems. This means taking a proactive approach to identifying and addressing vulnerabilities that could be exploited by attackers. One way to do this is by adopting a \u201cshift left\u201d or \u201cleft of shift left\u201d approach, which involves integrating security practices early in the development process. This approach allows developers to identify and address potential vulnerabilities before they become threats, reducing the risk of exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, federal agencies need to consider the lineage of any AI applications being used, understanding that key vulnerabilities may have been overlooked during the build phase. Being vigilant and attesting AI-based software is critical to fortifying an organization\u2019s defenses against evolving cyber threats, ensuring the integrity of systems, and maintaining a robust security posture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Software is at the pulse of how federal agencies operate today. It\u2019s critical that organizations stay ahead of software maintenance and security to protect the software supply chain and prevent a compromise of national security. By starting with these three tips, federal organizations can put themselves in a better position to address today\u2019s top threats to the software supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nick Mistry is SVP and CISO of <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.lineaje.dev%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7C5456988a9e194b7b5ef808dc3e25b0af%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638453578936031853%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=Qi5yabZ99xTvBv1S%2Bp7v0v8qFrNfPbE%2BAqSzQ4kN2Co%3D&#038;reserved=0\">Lineaje<\/a>, a provider of Continuous Software Supply Chain Security Management services to companies and government.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the evolution of AI, machine learning, and large language models, it&#8217;s critical that federal agencies have the right tools and processes in place.<\/p>\n","protected":false},"author":7,"featured_media":79166,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":26,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[112,113,31,14,26],"tags":[],"coauthors":[5938],"class_list":["post-27376","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-cybersecurity","category-home","category-it-networks","category-opinions"],"acf":{"subheadline":"","legacy_arc_id":"R5GZCHJLURDSNEBLVW4KQWFUQQ","arc_canonical_url":"\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Three tips for securing the federal software supply chain - Federal Times<\/title>\n<meta name=\"description\" content=\"With the evolution of AI, machine learning, and large language models, it&#039;s critical that federal agencies have the right tools and processes in place.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Three tips for securing the federal software supply chain\" \/>\n<meta property=\"og:description\" content=\"With the evolution of AI, machine learning, and large language models, it&#039;s critical that federal agencies have the right tools and processes in place.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-13T17:39:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T05:09:11+00:00\" \/>\n<meta name=\"author\" content=\"Nick Mistry\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nick Mistry\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Three tips for securing the federal software supply chain\",\n\t            \"datePublished\": \"2024-03-13T17:39:17+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:09:11+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/\"\n\t            },\n\t            \"wordCount\": 914,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1091956764.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Artificial Intelligence\",\n\t                \"Cybersecurity\",\n\t                \"Home\",\n\t                \"IT &amp; Networks\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/\",\n\t            \"name\": \"Three tips for securing the federal software supply chain - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1091956764.jpg.jpg\",\n\t            \"datePublished\": \"2024-03-13T17:39:17+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:09:11+00:00\",\n\t            \"description\": \"With the evolution of AI, machine learning, and large language models, it's critical that federal agencies have the right tools and processes in place.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1091956764.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1091956764.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2024\\\/03\\\/13\\\/three-tips-for-securing-the-federal-software-supply-chain\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/\",\n\t                    \"ad_zone\": \"opinions\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Three tips for securing the federal software supply chain\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Three tips for securing the federal software supply chain - Federal Times","description":"With the evolution of AI, machine learning, and large language models, it's critical that federal agencies have the right tools and processes in place.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","og_locale":"en_US","og_type":"article","og_title":"Three tips for securing the federal software supply chain","og_description":"With the evolution of AI, machine learning, and large language models, it's critical that federal agencies have the right tools and processes in place.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","og_site_name":"Federal Times","article_published_time":"2024-03-13T17:39:17+00:00","article_modified_time":"2026-08-08T05:09:11+00:00","author":"Nick Mistry","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Nick Mistry","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Three tips for securing the federal software supply chain","datePublished":"2024-03-13T17:39:17+00:00","dateModified":"2026-08-08T05:09:11+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/"},"wordCount":914,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1091956764.jpg.jpg","articleSection":["Artificial Intelligence","Cybersecurity","Home","IT &amp; Networks","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/","name":"Three tips for securing the federal software supply chain - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1091956764.jpg.jpg","datePublished":"2024-03-13T17:39:17+00:00","dateModified":"2026-08-08T05:09:11+00:00","description":"With the evolution of AI, machine learning, and large language models, it's critical that federal agencies have the right tools and processes in place.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1091956764.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1091956764.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2024\/03\/13\/three-tips-for-securing-the-federal-software-supply-chain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/","ad_zone":"opinions"},{"@type":"ListItem","position":3,"name":"Three tips for securing the federal software supply chain"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1091956764.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/27376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=27376"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/27376\/revisions"}],"predecessor-version":[{"id":27386,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/27376\/revisions\/27386"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=27376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=27376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=27376"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=27376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}