diff --git a/README.md b/README.md index 66ed87c..c0f8ce9 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,7 @@
Chain-bench is an open-source tool for auditing your software supply chain stack for security compliance based on a new - CIS Software Supply Chain benchmark. + CIS Software Supply Chain benchmark. The auditing focuses on the entire SDLC process, where it can reveal risks from code time into deploy time. To win the race against hackers and protect your sensitive data and customer trust, you need to ensure your code is compliant with your organization’s policies.
@@ -46,7 +46,7 @@ The auditing focuses on the entire SDLC process, where it can reveal risks from # Introduction -Chain-bench is an open-source tool for auditing your software supply chain stack for security compliance based on a new [CIS Software Supply Chain benchmark](https://workbench.cisecurity.org/communities/142). +Chain-bench is an open-source tool for auditing your software supply chain stack for security compliance based on a new [CIS Software Supply Chain benchmark](/docs/CIS-Software-Supply-Chain-Security-Guide-v1.0.pdf). The auditing focuses on the entire SDLC process, where it can reveal risks from code time into deploy time. # Quick start diff --git a/docs/CIS-Software-Supply-Chain-Security-Guide-v1.0.pdf b/docs/CIS-Software-Supply-Chain-Security-Guide-v1.0.pdf new file mode 100644 index 0000000..e74fdf3 Binary files /dev/null and b/docs/CIS-Software-Supply-Chain-Security-Guide-v1.0.pdf differ