Software Supply Chain Risk Management: From Products to Systems of Systems

SEI Report
In this report, the authors consider current practices in software supply chain analysis and suggest some foundational practices.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2010-TN-026
DOI (Digital Object Identifier)
10.1184/R1/6584210.v1

Abstract

Supply chains are usually thought of as manufacturing and delivering physical items, but there are also supply chains associated with the development and operation of a software system. Software supply chain research does not have decades of evidence to draw on, as with physical-item supply chains. Taking a systems perspective on software supply chain risks, this report considers current practices in software supply chain analysis and suggests some foundational practices. The product and supplier selection criteria for system development depend on how a product is used in a system. While many of the criteria for the selection of product suppliers and system development contractors are the same, there is also a significant difference between these kinds of acquisitions. Product development is completed in advance of an acquirer’s product and supplier assessment. There is no guarantee that current supplier development practices were used for a specific product. For custom system acquisitions, acquirers can and should actively monitor both contractor and product supply chain risks during development. This report suggests contractor and acquirer activities that support the management of supply chain risks.

Cite This SEI Report

Ellison, R., Alberts, C., Creel, R., Dorofee, A., & Woody, D. (2010, December 1). Software Supply Chain Risk Management: From Products to Systems of Systems. (SEI Report CMU/SEI-2010-TN-026). Retrieved August 16, 2026, from https://doi.org/10.1184/R1/6584210.v1.

@techreport{ellison_2010,
author={Ellison, Robert and Alberts, Christopher and Creel, Rita and Dorofee, Audrey and Woody, Dr. Carol},
title={Software Supply Chain Risk Management: From Products to Systems of Systems},
month={Dec},
year={2010},
number={{CMU/SEI-2010-TN-026},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/6584210.v1},
url={https://doi.org/10.1184/R1/6584210.v1},
note={Accessed: 2026-Aug-16}
}

Ellison, Robert, Christopher Alberts, Rita Creel, Audrey Dorofee, and Dr. Carol Woody. "Software Supply Chain Risk Management: From Products to Systems of Systems." (CMU/SEI-2010-TN-026). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, December 1, 2010. https://doi.org/10.1184/R1/6584210.v1.

R. Ellison, C. Alberts, R. Creel, A. Dorofee, and D. Woody, "Software Supply Chain Risk Management: From Products to Systems of Systems," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-2010-TN-026, 1-Dec-2010 [Online]. Available: https://doi.org/10.1184/R1/6584210.v1. [Accessed: 16-Aug-2026].

Ellison, Robert, Christopher Alberts, Rita Creel, Audrey Dorofee, and Dr. Carol Woody. "Software Supply Chain Risk Management: From Products to Systems of Systems." (SEI Report CMU/SEI-2010-TN-026). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Dec. 2010. https://doi.org/10.1184/R1/6584210.v1. Accessed 16 Aug. 2026.

Ellison, Robert; Alberts, Christopher; Creel, Rita; Dorofee, Audrey; & Woody, Dr. Carol. Software Supply Chain Risk Management: From Products to Systems of Systems. CMU/SEI-2010-TN-026. Software Engineering Institute. 2010. DOI: 10.1184/R1/6584210.v1. https://doi.org/10.1184/R1/6584210.v1