This document discusses the importance of DevSecOps and securing the software supply chain. It notes that modern applications and containers are increasingly assembled from many components, with 80-90% consisting of assembled parts. However, many open source components have known vulnerabilities, with only around 15-16% being fixed. It advocates for treating security as a system property and not passing defects downstream. The rewards of a trusted software supply chain include improvements like 90% faster deployments and 48% better application quality. Businesses are ultimately responsible for securing their data and systems.