Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Software supply chain visibility: what it means for appsec teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Kaltura reports that OX Active ASPM helped cut false positives by 80% and increase critical issue resolution by 40% while extending code-to-cloud visibility across its software supply chain, according to OXSecurity. The real lesson is that security tooling sprawl slows delivery when prioritisation and workflow automation are not aligned to engineering reality.

NHIMG editorial — based on content published by OXSecurity: Kaltura strengthens software supply chain security with Active ASPM

By the numbers:

Questions worth separating out

Q: How should security teams reduce tool sprawl in software supply chain security programmes?

A: Security teams should consolidate findings into a small number of decision points rather than more dashboards.

Q: Why do false positives slow down appsec and DevSecOps programmes?

A: False positives slow programmes because engineers stop trusting findings that do not reliably predict real risk.

Q: What breaks when code-to-cloud visibility is missing in software supply chain security?

A: When code-to-cloud visibility is missing, teams cannot trace how a finding moves from source to build to deployment and runtime impact.

Practitioner guidance

  • Map security findings to engineering decision paths Define which findings trigger immediate remediation, which enter backlog, and which are suppressed with documented justification.
  • Measure alert quality against remediation speed Track whether reductions in false positives shorten time to fix critical issues and improve engineer trust in the platform.
  • Treat CI/CD runners and pipeline service accounts as governed identities Inventory the non-human identities that can build, sign, approve, or deploy software, then review their access scope, rotation, and offboarding controls.

What's in the full article

OXSecurity's full case study covers the operational detail this post intentionally leaves for the source:

  • Specific platform workflow design used to route, prioritise, and automate findings across Kaltura's development lifecycle.
  • Detailed account of how OSC&R-based risk management was adapted to the company's software supply chain.
  • Implementation detail on how code-to-cloud visibility was applied without disrupting existing development operations.
  • The full outcome narrative behind false-positive reduction and critical issue handling across teams.

👉 Read OXSecurity's case study on Kaltura's software supply chain security programme →

Software supply chain visibility: what it means for appsec teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Software supply chain governance has become a prioritisation problem, not just a scanning problem. The article shows that tool proliferation and alert noise can slow deployments as effectively as a real vulnerability. That is the key governance failure mode in modern appsec programmes: teams know too much and decide too little. The practical conclusion is that security value now depends on triage quality, not scan volume.

A question worth separating out:

Q: How do you know if appsec automation is actually improving governance?

A: You know automation is working when it shortens decision time, improves critical fix rates, and reduces manual back-and-forth at triage. If the programme still depends on human interpretation for every alert, automation has only scaled output, not control.

👉 Read our full editorial: Software supply chain visibility is now an appsec governance issue



   
ReplyQuote
Share: