The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
Liming Dong, Sung Une Lee, Zhenchang Xing, Muhammad Ejaz Ahmed, Stefan Avgoustakis

TL;DR
This paper develops a comprehensive checklist of 80 questions to evaluate and improve software supply chain security in critical infrastructure, addressing gaps in existing frameworks and emphasizing a context-aware approach.
Contribution
It introduces a structured
Findings
Few frameworks are tailored to critical infrastructure sectors.
Identified gaps between existing guidance and sector-specific needs.
Proposed a multi-layered checklist for practical security assessment.
Abstract
The increasing frequency and sophistication of software supply chain attacks pose severe risks to critical infrastructure sectors, threatening national security, economic stability, and public safety. Despite growing awareness, existing security practices remain fragmented and insufficient, with most frameworks narrowly focused on isolated life cycle stages or lacking alignment with the specific needs of critical infrastructure (CI) sectors. In this paper, we conducted a multivocal literature review across international frameworks, Australian regulatory sources, and academic studies to identify and analyze security practices across the software supply chain, especially specific CI sector. Our analysis found that few existing frameworks are explicitly tailored to CI domains. We systematically leveraged identified software supply chain security frameworks, using a "4W+1H" analytical…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
