Cloud Security & SBOM
Software Bill of Materials (SBOM)
Angriffe auf die IT Supply Chain haben in den letzten Jahren zugenommen und basieren auf zwei Hauptfaktoren:
1. Lieferanten und deren Komponenten genießen oft ein hohes Vertrauen und weitgehende Rechte.
2. Die Transparenz über die genaue Zusammensetzung dieser Komponenten ist häufig unzureichend.
Diese Kombination führt dazu, dass Unternehmen kaum in der Lage sind, Risiken in der IT Supply Chain proaktiv zu erkennen oder entsprechende Angriffe abzuwehren. Vielmehr müssen sie sich weitgehend auf ihre Zulieferer verlassen.
"Software Bills of Materials" (SBOM), also Software-Stücklisten, bieten hier eine Lösung, indem sie eine detaillierte Auflistung der in einem Gerät, einer Software oder einem Dienst verwendeten Software-Komponenten liefern und so die Transparenz der Supply Chain erhöhen. Dies ermöglicht es Unternehmen, potenzielle Sicherheitslücken selbst und möglichst automatisiert zu bewerten und gezielte Schutzmaßnahmen zu ergreifen.
SBOMs liefern außerdem Informationen über die Lizenzen der verwendeten Komponenten und unterstützen so den Abgleich der tatsächlichen Nutzung mit den Lizenzvorgaben. Zukünftig könnten SBOMs auch dazu beitragen, die Transparenz im Datenschutz zu erhöhen, indem sie Informationen darüber enthalten, welche Daten von welchen Systemen verarbeitet und gespeichert werden.
In Deutschland existieren derzeit keine expliziten zivilrechtlichen oder regulatorischen Vorgaben für die Erstellung und Verwendung von SBOMs. Es kann allerdings argumentiert werden, dass SBOMs Teil des "Standes der Technik" sind, wie ihn verschiedene Gesetze fordern. Zudem wird der von der Europäischen Kommission vorbereitete Cyber Resilience Act (CRA) Hersteller verpflichten, für in der EU vertriebene Produkte SBOMs bereitzustellen. In den USA wurde durch eine Executive Order vom Mai 2021 die Bereitstellung und Nutzung von SBOMs für Software, die an die U.S. Administration geliefert wird, bereits vorgeschrieben. Unternehmen sollten deshalb bereits heute Klauseln zur Verpflichtung der Lieferung und Aktualisierung von SBOMs in ihre Verträge mit Softwarelieferanten und Diensteanbietern aufnehmen.
Der TeleTrusT-Leitfaden "Software Bill of Materials" (SBOM) beschreibt auch verfügbare SBOM-Tools sowie zukünftige Anforderungen an diese Werkzeuge, um vor allem die IT-Sicherheit weiter zu verbessern.
Summary
Attacks on the IT supply chain have increased in recent years and are based on two main factors:
1. Suppliers and their components often enjoy a high level of trust and extensive rights.
2. There is often insufficient transparency about the exact composition of these components.
This combination means that companies are hardly in a position to proactively recognise risks in the IT supply chain or ward off corresponding attacks. Instead, they have to rely largely on their suppliers.
‘Software Bills of Materials (SBOMs) offer a solution here by providing a detailed list of the software components used in a device, software or service, thereby increasing the transparency of the supply chain. This enables companies to assess potential security vulnerabilities themselves, as automatically as possible, and take targeted protective measures.
SBOMs also provide information about the licences of the components used and thus support the comparison of actual usage with the licence specifications. In the future, SBOMs could also help to increase transparency in data protection by providing information on which data is processed and stored by which systems.
In Germany, there are currently no explicit civil law or regulatory requirements for the creation and use of SBOMs. However, it can be argued that SBOMs are part of the ‘state of the art' as required by various laws. In addition, the Cyber Resilience Act (CRA) being prepared by the European Commission will oblige manufacturers to provide SBOMs for products sold in the EU. In the USA, an Executive Order from May 2021 has already made the provision and use of SBOMs mandatory for software supplied to the U.S. Administration. Companies should therefore already include clauses on the obligation to provide and automate SBOMs in their contracts with software suppliers and service providers.
The TeleTrusT Guideline ‘Software Bill of Materials' (SBOM) also describes available SBOM tools as well as future requirements for these tools in order to further improve IT security in particular.
Download
Cloud Supply Chain Security
Supply-Chain-Attacken haben in letzter Zeit deutlich zugenommen und betreffen auch bekannte Unternehmen. Die Attacken erfolgen über vertrauenswürdig eingestufte Komponenten und IT Services Dritter und sind daher von Anwendern schwer zu verhindern. Der TeleTrusT-Leitfaden beschreibt neben Software Bill of Materials (SBOM) weitere Schutzmaßnahmen, die von Anwenderunternehmen zur Verbesserung der Cloud Supply Chain Security getroffen werden können.
In der IT ist die Supply Chain die Lieferkette aller Teilprodukte und Lieferungen, aus denen sich ein IT Service oder eine Anwendung zusammensetzt. Für jede Art von Software, aber insbesondere für Cloud-Dienste, besteht eine solche Lieferkette aus unzähligen Lieferanten und Produkten, die entweder direkt oder indirekt genutzt werden oder zur Erstellung oder Ausführung der Teile beitragen. Im besten Fall wird der Produzent oder Anbieter der Teile die direkt genutzten Komponenten selbst auf Sicherheitseigenschaften überprüfen. Der Anwender hat aber normalerweise weder die Möglichkeit, die Nutzung einer betroffenen Komponente festzustellen, noch auf eine Behebung von Schwachstellen hinzuwirken - ein inakzeptabler Zustand.
Um das Problem der mangelnden Transparenz zu lösen, führt der Weg über die Software Bill of Materials (SBOM). Eine SBOM ist eine Aufstellung aller Komponenten, die in einer Software-Anwendung enthalten sind. Wenn neue Erkenntnisse zu Fehlern und Schwachstellen in diesen Komponenten auftauchen, können Anwender schnell ermitteln, ob sie möglicherweise betroffen sind und die von ihnen genutzten Anwendungen gefährdet sind. Es wird erwartet, dass sich die Bereitstellung von SBOMs durch Lieferanten und Betreiber von Software und Services zum Marktstandard entwickelt.
Summary
Supply chain attacks have increased significantly and also affect well-known providers. The attacks are carried out via trusted third-party components and IT services and are therefore difficult for users to prevent.
In IT, the supply chain is the supply chain of all sub-products and deliveries that make up an IT service or application. For any type of software, but especially for cloud services, such a supply chain consists of countless suppliers and products that are either used directly or indirectly, or contribute to the creation or execution of the parts. In the best case scenario, the producer or supplier of the parts will check the directly used components for security properties themselves. However, the user usually has neither the possibility to determine the use of an affected component nor to work towards the elimination of vulnerabilities - an unacceptable situation.
It is difficult for users to assess risks in the supply chain, and usually impossible for small and medium-sized companies. Users therefore rely on risk assessments and protective measures from providers without being able to assess and understand these in detail or even come to their own current assessment. As a result, they are almost completely dependent on the provider in the event of attacks.
The way to solve the problem of a lack of transparency is via a software bill of materials (SBOM). An SBOM is a list of all components contained in a software application. It thus creates transparency with regard to the software components used in an application. When applied to other elements of the supply chain (i.e. extended to hardware, cloud services, etc.), the concept allows complete transparency of all components used. If new findings emerge regarding errors and gaps in these components, users can quickly determine whether they are potentially affected and whether the applications they are using are at risk. If necessary, they can then take their own measures or decide not to use them temporarily.
However, the static provision of SBOMs, for example at the time the contract is concluded, is not sufficient. Instead, providers need to provide this information dynamically. This means that this information must be up-to-date at all times, even after updates. Providers must also receive up-to-date information on the components they use and pass it on to their users. This type of provision of SBOMs does not yet exist. Approaches exist, but are incompatible with each other in parts.
Users can make a significant contribution to improving security in the supply chain if they include the provision of SBOMs by providers in their catalog of requirements. For their part, providers should make this information available to their users. The transparency gained will enable providers and users to actively manage cyber security rather than just reacting to incidents.
This guide describes protective measures that user companies can take to improve IT security despite a lack of transparency and the inability to directly influence elements of the supply chain. It also contains a suggestion on how transparency about the supply chain and the elements used can be improved, even when using cloud services.
Download
Cloud Supply Chain Security
Cloud Security - Sichere Nutzung von Cloud-Anwendungen (2021)
Cloud Computing ist inzwischen ein breit akzeptiertes IT-Betriebsmodell und wird von den allermeisten Unternehmen genutzt. Auch viele IT-Anbieter haben in ihrer Strategie auf "Cloud First" gewechselt, zum Teil sogar auf "Cloud Only". Die Bedrohungslage hat sich ebenfalls verändert: Cloud-Plattformen sind zunehmend im Blickfeld von Cybercrime. Die sichere Nutzung von Cloud Services ist deshalb ein zentraler Baustein der IT-Sicherheit von Unternehmen insgesamt. Der TeleTrusT-Leitfaden "Cloud Security" richtet sich vorwiegend an kleine und mittlere Unternehmen. Er beginnt mit einer systematischen Betrachtung der Risiken bei der Nutzung von Cloud-Diensten, gegliedert nach allgemeinen IT-Risiken, Cloud-spezifischen Risiken und rechtlichen Anforderungen. Betrachtet werden auch die Sicherheitsvorteile von Cloud Services.
Der Leitfaden zeigt technische, organisatorische und rechtliche Maßnahmen zur Reduktion und Beherrschung ermittelter Risiken auf. Neben Mechanismen und Konfigurationsmöglichkeiten, die integraler Bestandteil der Cloud-Dienste sind, wird fokussiert auf externe Sicherungsmechanismen eingegangen: Identity Provider, Cloud Access Security Broker (CASB), Cloud Encryption Gateways, E-Mail Security Gateways, Cloud VPNs, Cloud Firewalls, Confidential Computing, Backup und Notfallplanung.
Im Bereich organisatorischer Maßnahmen wird auf die Aufgabenverteilung zwischen Anbieter und Nutzer sowie auf die Vertragsgestaltung eingegangen. Der Leitfaden schließt mit einer Betrachtung von Testaten und Zertifikaten im Cloud-Umfeld.