risk-management
Safeguard articles tagged "risk-management" — guides, analysis, and best practices for software supply chain and application security.
36 articles
Embedding security-by-design into DevSecOps risk management across the SDLC
NIST's SSDF turns 'shift left' into eleven concrete practices — but a framework on paper doesn't stop a bad merge. Here's how to make it enforceable.
A practical AppSec maturity model: five stages, self-assessment included
OWASP SAMM v2 scores 15 practices on a 0–3 scale; BSIMM15 measured 121 firms and found SCA adoption up 67%. Here's a five-stage model to self-assess against.
Software Supply Chain Security for CISOs
The CISO does not write the vulnerable dependency, but answers for it to the board, the auditor, and the regulator. Here is how to run a supply chain program that stands up to all three.
Reading Between the Lines of Vendor Research Reports: A M...
Vendor-sponsored security reports shape budgets and policy, but their methodologies rarely survive scrutiny. Here's how to read them critically.
What Is a Vulnerability in Cyber Security? A Plain-English Guide
A vulnerability in cyber security is a weakness an attacker can exploit. Here is how vulnerabilities differ from threats and risks, and how teams find and fix them.
How Application Security Risk Management Actually Works in Practice
A working model for application security risk management: how to inventory assets, rate risk you can act on, prioritize by exploitability and impact, and prove the program is reducing risk.
Risk Management Applications: How to Secure the Tools You Rely On
Risk management applications concentrate your most sensitive data, which makes them a target. Here is how to think about securing the software that manages your risk.
Vulnerability Prioritization in 2025: EPSS, VEX, and the End of CVSS-Only Triage
CVSS scores alone cannot tell you what to patch first. EPSS exploit prediction and VEX documents are reshaping how mature security teams prioritize vulnerabilities at scale.
What Is a Security Control?
A security control is a safeguard that prevents, detects, or responds to threats to reduce risk. Learn the types, categories, and how frameworks organize them.
Managing risk in the software supply chain
Chainguard hardens base images, but that's one slice of supply chain risk. Here's what SolarWinds, Log4Shell, and XZ Utils reveal about the gaps — and how to close them.
Software Supply Chain Security: An Executive Guide for 2025
Software supply chain attacks have surged 742% since 2019. This guide cuts through the noise to explain what executives need to know, what questions to ask, and where to invest.
CVSS v4: What Changed and Why It Matters
CVSS v4 reworks how vulnerability severity is scored, dropping the confusing Scope metric and adding finer-grained inputs. Here is what actually changed from v3.1.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.