{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:36:38Z","timestamp":1784997398336,"version":"3.55.0"},"reference-count":10,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2022,3,1]],"date-time":"2022-03-01T00:00:00Z","timestamp":1646092800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,3,1]],"date-time":"2022-03-01T00:00:00Z","timestamp":1646092800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,3,1]],"date-time":"2022-03-01T00:00:00Z","timestamp":1646092800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Secur. Privacy"],"published-print":{"date-parts":[[2022,3]]},"DOI":"10.1109\/msec.2022.3142338","type":"journal-article","created":{"date-parts":[[2022,3,24]],"date-time":"2022-03-24T21:34:08Z","timestamp":1648157648000},"page":"96-100","source":"Crossref","is-referenced-by-count":90,"title":["Top Five Challenges in Software Supply Chain Security: Observations From 30 Industry and Government Organizations"],"prefix":"10.1109","volume":"20","author":[{"given":"William","family":"Enck","sequence":"first","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref4","year":"2021","journal-title":"Chatham house rule"},{"key":"ref3","author":"kelly","year":"2021","journal-title":"Google and Microsoft promise billions to help bolster us cybersecurity"},{"key":"ref10","author":"munroe","year":"0","journal-title":"Dependency"},{"key":"ref6","year":"2019","journal-title":"H R 5793&#x2013;Cyber Supply Chain Management and Transparency Act of 2014"},{"key":"ref5","year":"2019","journal-title":"Survey of existing SBOM formats and standards"},{"key":"ref8","article-title":"What are weak links in the NPM supply chain?","author":"zahan","year":"0","journal-title":"Proc Int Conf Softw Eng Softw Eng Pract"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/358198.358210"},{"key":"ref2","year":"2021","journal-title":"Improving the nation&#x2019;s cybersecurity"},{"key":"ref9","first-page":"1393","article-title":"In-toto: Providing farm-to-table guarantees for bits and bytes","author":"torres-arias","year":"0","journal-title":"Proc Usenix Security Symp"},{"key":"ref1","year":"2021","journal-title":"2021 state of the software supply chain"}],"container-title":["IEEE Security &amp; Privacy"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8013\/9740698\/09740718.pdf?arnumber=9740718","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,19]],"date-time":"2022-05-19T20:24:41Z","timestamp":1652991881000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9740718\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3]]},"references-count":10,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/msec.2022.3142338","relation":{},"ISSN":["1540-7993","1558-4046"],"issn-type":[{"value":"1540-7993","type":"print"},{"value":"1558-4046","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3]]}}}