{"id":51658,"date":"2022-09-29T07:17:00","date_gmt":"2022-09-28T23:17:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=51658"},"modified":"2022-09-28T19:19:04","modified_gmt":"2022-09-28T11:19:04","slug":"all-roads-lead-to-transparency","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/09\/29\/all-roads-lead-to-transparency\/","title":{"rendered":"All roads lead to transparency"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Anton Ivanov<\/em><br><em>Chief Technology Officer, Kaspersky<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Digital transformation, that\u2019s been boosted by the pandemic, has reached an unprecedented scale, with IDC <a rel=\"noreferrer noopener\" href=\"https:\/\/www.idc.com\/getdoc.jsp?containerId=prUS48372321\" target=\"_blank\">expecting<\/a> its global spending to reach $2.8 trillion within three years. Companies shifting their businesses online inevitably led to an increased adoption of digital products and a surge in IT expenditure. According to rough <a rel=\"noreferrer noopener\" href=\"https:\/\/www.statista.com\/statistics\/1233538\/average-number-saas-apps-yearly\/#:~:text=In%202021%2C%20organizations%20worldwide%20were,by%20companies%20has%20constantly%20increased\" target=\"_blank\">estimates<\/a>, an average organization used about 110 different software-as-a-service applications in 2021. In comparison, that figure stood at 16 just five years ago. It\u2019s clear that we are currently in a stage of high software consumption. What isn\u2019t clear though is whether it has already peaked or if the peak is yet to come.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a cybersecurity perspective, a business\u2019 reliance on numerous types of software is a big issue as threat actors can benefit from the expanded attack surface. A recent global <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/linuxfoundation.org\/wp-content\/uploads\/LFResearch_SBOM_Report_020422.pdf\">survey<\/a> of over 400 companies showed that 98% of organizations were concerned about the security of their software. However, there isn\u2019t much that they can do about it, aside from diligently patching their software as soon as updates are available.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, on a level of mature enterprise, sustainability of IT infrastructure that includes various types of software depends on how much we know about each solution and our visibility into them. IT products are developed with extensive use of various open source libraries and elements sourced from third parties. With dozens and hundreds of software solutions in use, this means that achieving a high level of visibility is extremely challenging. Without clear security requirements for evaluating software security and promoting greater transparency, the cyber domain is likely to remain under limited control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the concepts aimed at streamlining the connections across software supply chains is Software Build of Materials (SBOM). Borrowed from manufacturing, where the \u201cBuild of Materials\u201d represents a list of items used in a product, SBOM is a de facto list of components that make up a software, containing comprehensive information and describing the relationships between each element. By having SBOMs in place, businesses have more chances of coping with security vulnerabilities and cybersecurity risks in a prompt manner by employing automation tools which can track newly identified flaws across them all.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the fall of 2021, as part of its transparency efforts, Kaspersky <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/usa.kaspersky.com\/about\/press-releases\/2021_kaspersky-announces-software-bill-of-materials-available-for-its-customers-and-partners\">made<\/a> its SBOMs available at the company\u2019s Transparency Centers. These centers primarily serve as facilities for the review of the company&#8217;s code, software updates, threat detection rules and other technical and business processes. Along with measures implemented by Kaspersky as part of its <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/transparency\">Global Transparency Initiative<\/a> (GTI), the inclusion of SBOMs aims to empower our customers and partners with the information on how exactly our products are designed, what components they are made of, and how they operate. In doing this, our key goal is to ensure greater visibility into our solutions, our work and to give firm assurance in the security and integrity of our products.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite the fact that regulators and private players have <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/venturebeat.com\/2022\/02\/02\/the-state-of-software-bill-of-materials-sbom-growth-could-bolster-software-supply-chains\/\">praise<\/a>d the SBOM concept as crucial for ensuring sustainable and safe software use, fresh statistics <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.linuxfoundation.org\/tools\/the-state-of-software-bill-of-materials-sbom-and-cybersecurity-readiness\/\">show<\/a> that fewer than a half of software developers use SBOMs to some extent today. On top of that, a mere 18% of companies use SBOMs across all segments of their business or have established practices that include the use of SBOMs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The situation could potentially change in the near future as some governments can start considering SBOMs a necessary measure to enhance risk management in supply chains. The first being the US where, after the SolarWinds incident, SBOM has been <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\">promoted<\/a> at a government level to become a wide-industry effort. Hopefully, the SBOM concept for software transparency will turn into an international effort.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Speaking of clear security requirements for software security, the European Union has also <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/news\/commission-invites-citizens-and-organisations-share-their-views-european-cyber-resilience-act\">started<\/a> a wider discussion on a legal framework that would bring together cybersecurity rules for digital products and services. It is likely that other governments will follow the EU\u2019s lead, ensuring software vendors place adequate cybersecurity safeguards in their solutions, effectively respond to vulnerabilities throughout their products\u2019 lifecycle, and systematically provide information on the product\u2019s security. All these measures, while requiring greater transparency from software manufacturers, have the potential to enhance the security of products and build public trust in the digital economy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Kaspersky, the security of our users and customers is our first and foremost priority. The trust of our customers has always been seen as indispensable, and that\u2019s why we make every effort to provide them with as much visibility into our work as possible. In 2017 we launched our <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/transparency\">GTI<\/a> which was aimed at further strengthening our relationships with our partners and customers by boosting their assurance and trust in our solutions and services. We continue to develop and strengthen this initiative, for example, we have recently successfully renewed our <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2022_kaspersky-successfully-renews-soc-2-audit-by-big-four-firm\">SOC 2 audit<\/a> for the protection of the development and the release process of our antivirus basis by a Big Four firm.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The industry developments that we see today indicate that transparency is achieving greater prominence: this is reflected by developments within the industry and various governments\u2019 increasing their attention to greater security and integrity of software. Kaspersky, for its part, will seek to deliver solid support for this trend, making further continued investment in digital trust and transparency.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to rough estimates, an average organization used about 110 different software-as-a-service applications in 2021. In comparison, that figure stood at 16 just five years ago. It\u2019s clear that we are currently in a stage of high software consumption. What isn\u2019t clear though is whether it has already peaked or if the peak is yet to come.<\/p>\n","protected":false},"author":6,"featured_media":47550,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[101,54,2103],"class_list":["post-51658","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=51658"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51658\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/47550"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=51658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=51658"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=51658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}