A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t be your finish line.
From there, we tie the real-world scenario directly to CISSP Domain 8 Software Development Security and the secure SDLC. I lay out a clear, exam-friendly framework for assessing third-party and acquired software risk: Software Composition Analysis (SCA), Software Bill of Materials (SBOM), vendor and publisher risk assessment, and runtime plus pipeline controls. We talk about why SCA is necessary but incomplete, how a living SBOM enables fast exposure checks when a new campaign hits, and why Executive Order 14028 is pushing SBOM adoption into “expected” territory for many organisations.
We also get practical about CI/CD pipeline security: dependency pinning, trusted publishing workflows, signed commits, OIDC, and package signing and verification approaches like Sigstore and Cosign. Finally, we run through scenario-based practice questions that highlight common CISSP traps and the manager mindset the exam rewards. If you want more episodes like this, subscribe, share it with a developer or security lead, and leave a quick review so more CISSP candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Podden och tillhörande omslagsbild på den här sidan tillhör
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur. Innehållet i podden är skapat av Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur och inte av,
eller tillsammans med, Poddtoppen.