Ensuring software security is essential for any organization that wants to prevent risks from entering their software development lifecycle (SDLC). In this talk, we will explore the key principles of software security and how to integrate them into your development process. We’ll show you how to identify potential risks in your SDLC and provide you with practical solutions to mitigate them. Additionally, we’ll discuss the importance of software bill of materials (SBOM), and how it can help you to secure your software supply chain.