A little more than a week before the Colonial Pipeline attack, two government agencies issued an overview and guidance on how software buyers and vendors could identify, assess and mitigate software supply chain risks.
In that 16-page document, “Defending Against Software Supply Chain Attacks” the National Institute of Standards and…