| |
| dido:99_annexes:annex-b-terms-and-definitions:s:supply-chain_integrity [2026/07/13 12:40] – created nick_dido | dido:99_annexes:annex-b-terms-and-definitions:s:supply-chain_integrity [2026/07/18 12:33] (current) – external edit 127.0.0.1 |
|---|
| Supply-Chain Integrity is the condition in which the identities, origins, versions, relationships, transformations, and content of supply-chain elements remain accurate, complete, authorized, and protected from unauthorized alteration. | Supply-Chain Integrity is the condition in which the identities, origins, versions, relationships, transformations, and content of supply-chain elements remain accurate, complete, authorized, and protected from unauthorized alteration. |
| |
| The condition applies to source material, dependencies, tools, build processes, artefacts, manifests, signatures, evidence, transfer mechanisms, repositories, and associated [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]. | The condition applies to source material, dependencies, tools, build processes, artifacts, manifests, signatures, evidence, transfer mechanisms, repositories, and associated [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]. |
| |
| Supply-Chain Integrity depends on controls such as [[dido:99_annexes:annex-b-terms-and-definitions:v:version_pinning|Version Pinning]], integrity verification, digital signatures, controlled repositories, change approval, access control, traceable transformations, and preservation of authoritative records. | Supply-Chain Integrity depends on controls such as [[dido:99_annexes:annex-b-terms-and-definitions:v:version_pinning|Version Pinning]], integrity verification, digital signatures, controlled repositories, change approval, access control, traceable transformations, and preservation of authoritative records. |
| |
| Within Crucible, Supply-Chain Integrity supports confidence that the artefacts built, transferred, imported, and deployed correspond to the approved inputs and controlled processes recorded for them. | Within Crucible, Supply-Chain Integrity supports confidence that the artifacts built, transferred, imported, and deployed correspond to the approved inputs and controlled processes recorded for them. |
| |
| ===== Definition ===== | ===== Definition ===== |
| ===== Source ===== | ===== Source ===== |
| |
| Generalized from cybersecurity, software supply-chain risk management, configuration management, provenance, and artefact-integrity usage and specialized for the Crucible architecture and operational model. | Generalized from cybersecurity, software supply-chain risk management, configuration management, provenance, and artifact-integrity usage and specialized for the Crucible architecture and operational model. |
| |
| ===== Note ===== | ===== Note ===== |