The OSC&R (Open Software Supply Chain Attack Reference), Open Visibility Exploitability eXchange (OpenVEX), a tool for addressing vulnerabilities in enterprise software, and cyber supply chain risk management (C-SCRM), are set to help enterprises combat supply chain attacks.