Meaning
Industrial frameworks for software security define the verification requirements for every stage of the build and distribution process. Implementing the supply chain levels for software artifacts helps protect against the injection of malicious code into a production environment. This model provides a set of tiers that increase in rigor as the risk profile of the application grows.
Provenance Track
Recording the origin of every component is a core requirement for the lower supply chain levels for software artifacts. This record shows where the code came from and who built it. Knowing the history of the software is the first step in defending against tampering.
Build Security
High tiers of the supply chain levels for software artifacts require that the build process happens in a secure and isolated environment. No human should be able to modify the code after it has been submitted for assembly. This isolation prevents the secret addition of backdoors or unauthorized features.
Maturity Grade
Organizations move through the supply chain levels for software artifacts as they improve their automation and verification tools. Each level represents a higher degree of confidence in the integrity of the final product. Reaching the highest grade requires a complete and verifiable history for every line of code.