Knowledgebase

Third-Party and Supply Chain Risk Print

  • devopsinfrastructure, devops, hacked, guide, howto, solution, zillionkinghost, hosting
  • 0

Risk you inherit.

WHERE IT COMES FROM

Dependencies in your code Base images Build tools and pipeline services Hosting and platform providers Services with access to your systems

WHAT THE RISK IS

A compromise reaching you through something you trusted.

WHAT TO DO ABOUT DEPENDENCIES

Pin versions Check for known vulnerabilities automatically Review what you actually need Remove what is unused

WHAT TO BE CAREFUL WITH

Packages with names similar to popular ones Packages with very few users Build scripts that execute on install

WHAT TO DO ABOUT SERVICES WITH ACCESS

Record them Grant the minimum Review periodically Revoke what is unused

WHAT TO ASK OF A PROVIDER

What they can access What happens if they are breached How they would tell you

WHAT TO REVIEW ANNUALLY

Every integration, and whether it is still needed.

WHAT YOU WILL FIND

Connections authorised years ago that nobody remembers.

WHAT TO REMOVE

Those.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot