was ist sbom
What’s in a software bill of materials?
An SBOM is a complete inventory of a codebase including the open source components,
the license and version information for those open source components,
and whether there are any known vulnerabilities in those components.
Why do organizations need a software Bill of Materials?
In 2021 there were several high-profile security breaches,
including Codecov, Kaseya, and most recently Apache Log4j.
These types of supply chain attacks prompted President Biden
to issue a cybersecurity executive order (EO) detailing guidelines for
how federal departments, agencies, and contractors doing business
with the government must secure their software. Among the recommendations
was a requirement for SBOMs, to ensure the safety and integrity of software
applications used by the federal government.
Although the EO is directed toward organizations doing business with
the government, these guidelines, including SBOMs, are likely to
become a de facto baseline for how all organizations
build, test, secure, and operate their software applications.