Software Supply Chain Glossary
A comprehensive collection of terms, concepts, and definitions related to software supply chain management.
C
Container Bill of Materials (CBOM)
A structured inventory that documents all components, dependencies, and configuration details within a container image, enabling enhanced visibility and security throughout the container lifecycle.
Cybersecurity and Infrastructure Security Agency (CISA)
A federal agency responsible for improving cybersecurity across government and critical infrastructure sectors, coordinating national cyber defense, and providing guidance on emerging security threats.
Code Signing
The process of digitally signing executables and software packages to verify the author's identity and ensure the code hasn't been altered or corrupted since signing.
Cryptography
The practice and study of techniques for securing communication and data through the use of mathematical algorithms, enabling confidentiality, integrity, authentication, and non-repudiation in software systems.