The Supply-Chain Levels for Software Artifacts is a great way to benchmark an organization's Supply-Chain Security. In this age of rising supply-chain attacks, it becomes imperative for organizations to approach Supply-Chain Security with a practical yet, comprehensive approach. I strongly believe the SLSA is useful for companies to get there.
This is a slide-deck of a talk I gave to the engineering team at Github. As part of their Day of Learning