{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T15:59:06Z","timestamp":1785340746142,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T00:00:00Z","timestamp":1785283200000},"content-version":"vor","delay-in-days":289,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2207008"],"award-info":[{"award-number":["2207008"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3733827.3765526","type":"proceedings-article","created":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T12:47:16Z","timestamp":1785329236000},"page":"26-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Establishing a Baseline of Software Supply Chain Security Task Adoption by Software Organizations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3300-6540","authenticated-orcid":false,"given":"Laurie","family":"Williams","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-3291-8457","authenticated-orcid":false,"given":"Samuel","family":"Migues","sequence":"additional","affiliation":[{"name":"Imbricate Security, Sterling, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,29]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Black Duck. 2025. Building Maturity In Maturity Model (BSIMM). https:\/\/www.blackduck.com\/services\/security-program\/bsimm-maturity-model.html (2025)."},{"key":"e_1_3_3_2_3_2","unstructured":"Cloud Native Computing Foundation. 2024. Software Supply Chain Best Practices v2. https:\/\/tag-security.cncf.io\/blog\/software-supply-chain-security-best-practices-v2\/ (2024)."},{"key":"e_1_3_3_2_4_2","unstructured":"Cyber Safety Review Board. 2022. Review of the December 2021 Log4j Event. https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CSRB-Report-on-Log4-July-11-2022_508.pdf."},{"key":"e_1_3_3_2_5_2","unstructured":"Cybersecurity and Infrastructure Security Agency. 2021. Joint Statement by the Federal Bureau of Investigation (FBI) the Cybersecurity and Infrastructure Security Agency (CISA) the Office of the Director of National Intelligence (ODNI) and the National Security Agency (NSA). https:\/\/www.cisa.gov\/news-events\/news\/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure-security-agency-0."},{"key":"e_1_3_3_2_6_2","unstructured":"Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA). 2024. Secure Software Development Attestation Form. https:\/\/www.cisa.gov\/sites\/default\/files\/2024-04\/Self_Attestation_Common_Form_FINAL_508c.pdf"},{"key":"e_1_3_3_2_7_2","volume-title":"Cybersecurity Maturity Model Certification (CMMC)","year":"2020","unstructured":"DoD. 2020. Cybersecurity Maturity Model Certification (CMMC). https:\/\/www.acq.osd.mil\/cmmc\/docs\/CMMC_ModelMain_V1.02_20200318.pdf"},{"key":"e_1_3_3_2_8_2","unstructured":"European Union. 2024. Horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168\/2013 and (EU) No 2019\/1020 and Directive (EU) 2020\/1828 (Cyber Resilience Act)."},{"key":"e_1_3_3_2_9_2","unstructured":"FireEye. 2020. Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor."},{"key":"e_1_3_3_2_10_2","unstructured":"Andres Freund. March 29 2024. backdoor in upstream xz\/liblzma leading to ssh server compromise. https:\/\/www.openwall.com\/lists\/oss-security\/2024\/03\/29\/4."},{"key":"e_1_3_3_2_11_2","unstructured":"Sivana Hamer Jacob Bowen Md\u00a0Nazmul Haque Robert Hines Chris Madden and Laurie Williams. 2025. Closing the Chain: How to reduce your risk of being SolarWinds Log4j or XZ Utils. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2503.12192 (2025)."},{"key":"e_1_3_3_2_12_2","unstructured":"Red Hat. March 29 2024. Urgent security alert for Fedora Linux 40 and Fedora Rawhide users. https:\/\/www.redhat.com\/en\/blog\/urgent-security-alert-fedora-40-and-rawhide-users."},{"key":"e_1_3_3_2_13_2","unstructured":"ISO. 2011. ISO\/IEC 27034 Application Security Standard. https:\/\/www.iso27001security.com\/html\/27034.html"},{"key":"e_1_3_3_2_14_2","unstructured":"ISO\/IEC. 2013. ISO\/IEC 27001: Information Security Management Report. https:\/\/www.iso.org\/isoiec-27001-information-security.html"},{"key":"e_1_3_3_2_15_2","unstructured":"ISO\/IEC. 2023. Information technology \u2014 OpenChain security assurance specification. https:\/\/openchainproject.org\/security-assurance (2023)."},{"key":"e_1_3_3_2_16_2","unstructured":"Sung\u00a0Une Lee Liming Dong Zhenchang Xing Muhammad\u00a0Ejaz Ahmed and Stefan Avgoustakis. 2025. Software Security Mapping Framework: Operationalization of Security Requirements. arxiv:https:\/\/arXiv.org\/abs\/2506.11051\u00a0[cs.SE] https:\/\/arxiv.org\/abs\/2506.11051"},{"key":"e_1_3_3_2_17_2","unstructured":"Linux Foundation. 2025. Open Source Project Security Baseline. https:\/\/github.com\/ossf\/security-baseline (2025)."},{"key":"e_1_3_3_2_18_2","unstructured":"Log4J. 2021. Apache Log4j Security Vulnerabilities. https:\/\/logging.apache.org\/log4j\/2.x\/security.html"},{"key":"e_1_3_3_2_19_2","volume-title":"Crossing the Chasm: Marketing and Selling High-tech Products to Mainstream Customers","author":"Moore G.A.","year":"1995","unstructured":"G.A. Moore. 1995. Crossing the Chasm: Marketing and Selling High-tech Products to Mainstream Customers. HarperBusiness. https:\/\/books.google.com\/books?id=sfGPzQEACAAJ"},{"key":"e_1_3_3_2_20_2","volume-title":"NIST Special Publication 800-53, Revision 5, Security and Privacy Controls forInformation Systems and Organizations","year":"2020","unstructured":"NIST. 2020. NIST Special Publication 800-53, Revision 5, Security and Privacy Controls forInformation Systems and Organizations. https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r5.pdf0"},{"key":"e_1_3_3_2_21_2","unstructured":"NIST. 2022. Secure Software Development Framework (SSDF). https:\/\/csrc.nist.gov\/projects\/ssdf (2022). Accessed: February 21 2025."},{"key":"e_1_3_3_2_22_2","unstructured":"NIST. 2024. Security Controls - NIST Glossary. https:\/\/csrc.nist.gov\/glossary\/term\/security_controls Accessed: February 19 2025."},{"key":"e_1_3_3_2_23_2","unstructured":"NIST. 2024. SP 800-161 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-161r1-upd1.pdf (2024)."},{"key":"e_1_3_3_2_24_2","unstructured":"NIST. February 26 2024. NIST Cybersecurity Framework. https:nvlpubs.nist.govnistpubsCSWPNIST.CSWP.29.pdf (February 26 2024)."},{"key":"e_1_3_3_2_25_2","unstructured":"OpenCRE. 2024. Open Common Requirement Enumeration. https:\/\/opencre.org\/ (2024)."},{"key":"e_1_3_3_2_26_2","unstructured":"OpenSSF. 2022. Software Supply Chain Consumption Framework (S2C2F). https:\/\/github.com\/ossf\/s2c2f (2022)."},{"key":"e_1_3_3_2_27_2","unstructured":"OpenSSF. 2022. Supply chain Levels for Software Artifacts (SLSA). https:\/\/slsa.dev\/ (2022)."},{"key":"e_1_3_3_2_28_2","unstructured":"OpenSSF. 2024. Best Practices Badge Program. https:\/\/www.bestpractices.dev\/en (2024)."},{"key":"e_1_3_3_2_29_2","unstructured":"OpenSSF. 2025. OpenSSF Scorecard - Security health metrics for Open Source."},{"key":"e_1_3_3_2_30_2","volume-title":"OWASP Application Security Verification Standard (ASVS)","year":"2020","unstructured":"OWASP. 2020. OWASP Application Security Verification Standard (ASVS). https:\/\/owasp.org\/www-project-application-security-verification-standard\/"},{"key":"e_1_3_3_2_31_2","unstructured":"OWASP. 2020. Software Assurance Maturity Model v2. https:\/\/drive.google.com\/file\/d\/1ZWMk4dpS3zpXjE28wi4cf5Lq6TUjeA5x\/view (2020)."},{"key":"e_1_3_3_2_32_2","unstructured":"OWASP. 2020. Software Component Verification Standard (SCVS). https:\/\/owasp-scvs.gitbook.io\/scvs\/ (2020)."},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.5555\/319568.319624"},{"key":"e_1_3_3_2_34_2","unstructured":"Russ Cox. 2024. Timeline of the xz open source attack. https:\/\/research.swtch.com\/xz-timeline."},{"key":"e_1_3_3_2_35_2","unstructured":"SolarWinds. 2021. SolarWinds Security Advisory. https:\/\/www.solarwinds.com\/sa-overview\/securityadvisory."},{"key":"e_1_3_3_2_36_2","unstructured":"Sonatype. 2024. State of the software supply chain: A Decade of Data. =https:\/\/www.sonatype.com\/state-of-the-software-supply-chain\/2024\/10-year-look."},{"key":"e_1_3_3_2_37_2","unstructured":"White House. 2021. Executive Order 14028 on Improving the Nation\u2019s Cybersecurity. https:\/\/www.federalregister.gov\/documents\/2021\/05\/17\/2021-10460\/improving-the-nations-cybersecurity (2021)."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","unstructured":"Laurie Williams Giacomo Benedetti Sivana Hamer Ranindya Paramitha Imranur Rahman Mahzabin Tamanna Greg Tystahl Nusrat Zahan Patrick Morrison Yasemin Acar Michel Cukier Christian K\u00e4stner Alexandros Kapravelos Dominik Wermke and William Enck. 2025. Research Directions in Software Supply Chain Security. ACM Trans. Softw. Eng. Methodol. (Jan. 2025). 10.1145\/3714464","DOI":"10.1145\/3714464"},{"key":"e_1_3_3_2_39_2","unstructured":"Laurie Williams Sammy Migues Jamie Boote and Ben Hutchison. 2025. Proactive Software Supply Chain Risk Management Framework (P-SSCRM) Version 1.01. https:\/\/arxiv.org\/pdf\/2404.12300 (2025)."},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00219"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00219"},{"key":"e_1_3_3_2_42_2","unstructured":"Shalanda\u00a0D. Young. 2022. M-22-18 Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/09\/M-22-18.pdf (2022)."},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"crossref","unstructured":"Nusrat Zahan Parth Kanakiya Brian Hambleton Shohanuzzaman Shohan and Laurie Williams. 2023. Openssf scorecard: On the path toward ecosystem-wide automated security metrics. IEEE Security & Privacy 21 6 (2023) 76\u201388.","DOI":"10.1109\/MSEC.2023.3279773"},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP58684.2023.00032"},{"key":"e_1_3_3_2_45_2","unstructured":"Nusrat Zahan and Laurie Williams. 2025. Prioritizing Security Practice Adoption: Empirical Insights on Software Security Outcomes in the npm Ecosystem. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2504.14026 (2025)."}],"event":{"name":"SCORED '25: Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses","location":"Taipei , Taiwan","acronym":"SCORED '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733827.3765526","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733827.3765526","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T15:12:08Z","timestamp":1785337928000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733827.3765526"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":44,"alternative-id":["10.1145\/3733827.3765526","10.1145\/3733827"],"URL":"https:\/\/doi.org\/10.1145\/3733827.3765526","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2026-07-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}