Advanced Software Supply Chain White Paper (2022) Co-authored by GBASE Released
Recently, the 2022 Guangdong-Hong Kong-Macao Greater Bay Area (Guangzhou) Forum on High-Quality Information Technology Development and Cybersecurity was successfully held in Guangzhou. At the forum, Dr. Chai Siyue from the Fifth Electronics Research Institute of MIIT released the IT Application Innovation Software Supply Chain White Paper (Draft for Comments) [hereinafter referred to as the White Paper], which systematically outlines the definition and connotation of proprietary software supply chains and introduces the categories and current state of software supply chain security. As a leading database provider, GBASE (General Data Technology Co., Ltd.) contributed to the compilation of the database-related software content in the white paper.
Dr. Chai emphasized that a software supply chain is a supply activity that transforms source code, components, runtime environments, intellectual property, etc. into specific products or services tailored to application requirements, delivers them through online and offline software delivery channels, and continuously operates them. It forms a multi-tier network-like supply-demand architecture composed of essential suppliers, intermediaries, and third-party service providers.
At present, China's software supply chain faces risks. Over 180,000 software quality defects and security vulnerabilities have been cataloged, and more than 800 known vulnerabilities have been exploited. The open-source software supply ecosystem is complex, making it urgent to systematically advance industry-level open-source governance. In addition, the abuse of intellectual property rights in open-source software also warrants attention.
Supply Chain Management Recommendations
First, pay attention to policy risks such as the U.S. stopping services or cutting off supplies in the ICT supply chain, and prioritize assessing supply chain standard risks (e.g., NIST, ISO) and data security risks of foreign DevSecOps software.
Second, accelerate the development of China's independent software supply chain standard system, driven by applications, to optimize evaluation indicators for self-developed software supply chains.
Third, accelerate the enhancement of industry-level public service capabilities for software supply chains.
New Expectations from Both Supply and Demand Sides
For information technology enterprises:
They should properly utilize open-source and third-party innovations, accurately assess and manage software supply chain risks, and release higher-quality code faster than competitors.
For user organizations:
Establish a software supply chain risk management system, assess risks under the existing framework, effectively conduct internal software lifecycle management, achieve traceability of software lifecycle information, and enable rapid response and remediation of risk vulnerabilities.
As a contributor to the Advanced Software Supply Chain White Paper, GBASE (General Data Technology Co., Ltd.) offers GBase database products with independently developed core technologies and underlying source code. It is one of the few independent database providers in China that focus on database product R&D and have achieved large-scale deployments in the finance and telecommunications industries. As a vital link in the software supply chain, GBASE will continue to strengthen its supply-side efforts, providing secure, stable, and superior database products and services for the construction of an advanced software supply chain in China.