Summary
The information below outlines the Activity 3.3.1 (Phase One) – Approved Binaries and Code of the Department of War (DoW) Zero Trust (ZT) Framework, focusing on the incorporation of supplier-sourcing risk evaluation and the use of approved vulnerability databases in Development, Security, and Operations (DevSecOps). It presents strategic insights that drive implementation and expected outcomes, including the integration of supplier-source risk evaluations for approved sources. This integration drives implementation and expected outcomes, which, in turn, drive the integration of supplier-source risk evaluations for approved sources. These outcomes also include adherence to industry standards for approved vulnerability databases in DevSecOps.