QNAP 新闻室
掌握 QNAP 最新的新闻信息、奖项并与我们团队联系
QNAP Strengthens Software Supply Chain Security, Improving NAS Software Compliance and Risk Management

2025 年 3 月 11 日– As cybersecurity threats escalate, managing risks in the software supply chain has become a key component for businesses to ensure information security. QNAP® Systems, Inc. is proactively strengthening its software supply chain security by maintaining a Software Bill of Materials (SBOM), enhancing risk management efficiency, and ensuring the security and transparency of its NAS software environment.
QNAP’s Cybersecurity Measures:
- SBOM Support and Software Transparency: By maintaining a comprehensive SBOM, QNAP tracks component versions and sources to ensure timely security updates. It adopts industry-standard formats (such as CycloneDX, SPDX) to enhance the license review process and ensuring compliance in sensitive industries, and performs Software Composition Analysis (SCA) to detect vulnerabilities in open-source components.
- Continuous Security Updates: Regular updates are released, and vulnerabilities are detected through automated tools, enhancing product and data security.
- Third-Party Security Reviews and Compliance Certifications: QNAP integrates the MITRE CVE and CISA KEV databases for rapid vulnerability response and follows international cybersecurity standards for reviews and testing.
- Internal Development with Multi-Layered Protection: QNAP adopts multi-layered protection measures, including physical security and intrusion detection systems, to safeguard the development process and user data.
QNAP continues its commitment to providing secure and reliable NAS solutions, strengthening software supply chain management to help businesses enhance cybersecurity resilience and ensure long-term stable operations. Click here to learn more about QNAP's software supply chain risk management.
关于 QNAP
QNAP 命名源自于高质量网络设备制造商(Quality Network Appliance Provider),我们致力研发软件应用,匠心优化硬件设计,并设立自有生产线以提供诸多且先进的科技解决方案。QNAP 专注于存储、网通及智能视讯产品创新,并提供 Cloud NAS 解决方案,通过软件订阅制及多元化服务管道建构崭新的科技生态圈。在 QNAP 的企业蓝图中,NAS 早已突破存储设备的框架,搭配云基础网络架构上的多项研发创新,协助客户高效率导入人工智能分析、边缘运算及信息整合应用,创造更大优势与价值。