compliance
Safeguard articles tagged "compliance" — guides, analysis, and best practices for software supply chain and application security.
475 articles
CI/CD Pipeline Audit Logging: What to Capture and Why
Your CI/CD pipeline is a high-value target. Without proper audit logging, you will not know when it has been compromised until it is too late.
SBOM Formats Compared: CycloneDX vs SPDX in 2022
Two SBOM standards are competing for adoption. CycloneDX and SPDX take fundamentally different approaches to describing software components. Here's what matters when choosing between them.
CISA Known Exploited Vulnerabilities Catalog Launched
CISA's KEV catalog changes vulnerability management from theoretical risk to confirmed exploitation. Here's what it means and how to use it for prioritization.
NTIA SBOM Minimum Elements: What Your SBOM Actually Needs to Contain
The NTIA published its minimum elements for SBOMs in July 2021. Here's a practical breakdown of what's required, what's optional, and where most organizations fall short.
Third-Party Risk Management for Software Vendors: Beyond the Questionnaire
Security questionnaires are still how most organizations evaluate vendor risk. They're also still mostly useless. Here's what actually works.
NIST SSDF Framework: A Practical Guide
The Secure Software Development Framework (SSDF) is becoming the baseline for federal software security. Here's what it contains and how to implement it.
Understanding SBOM Requirements Under EO 14028
Executive Order 14028 mandates SBOMs for federal software procurement. Here's a practical breakdown of what's required, what formats to use, and how to get compliant.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.