MITRE’s prototype Supply Chain Security System of Trust (SoT) Framework provides an evidence-based, customizable method for evaluating supply-chain risk throughout technology acquisition lifecycles. It covers 14 top-level trust-risk areas, roughly 200 sub-areas, and approximately 2,200 assessment questions, emphasizing supplier due diligence and an organization’s security posture.
The framework complements federal software-supply-chain objectives established under Executive Order 14028 and recognizes software bills of materials (SBOMs) as a key inventory and vulnerability-management control. SBOMs can help organizations identify exposure to disclosed component flaws such as Log4j, but they do not by themselves detect covert supplier compromises such as SolarWinds, remediate unpatched issues such as Follina, or create immediate breach-notification obligations; organizations need broader supplier-assurance and incident-response controls.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Robert Martin, a Senior Principal Engineer at MITRE, discussed software supply-chain risk management at the CAPEC Program User Summit.
Executive Order 14208 requires software vendors to provide an SBOM directly or publish one on a public website.
The National Telecommunications and Information Administration published "The Minimum Elements for a Software Bill of Materials (SBOM)," covering component data, automation support, and SBOM generation and use practices.
MITRE developed a prototype Supply Chain Security System of Trust framework to support scalable, evidence-based, customizable assessment of physical and digital supply-chain risks across acquisition lifecycles.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.