
#138 - Updating the Mindmap (with Rafeeq Rehman)
CISO Tradecraft®
00:00
The Importance of Software Build of Materials
S-bombs are a perfect solution but they certainly help a lot in terms of understanding when a commonly available library has a vulnerability analysis you can very quickly go to the executive team and say this does protect a service does not affect us yeah. so it seems to me you would be an advocate of the software build of materials concept absolutelyAbsolutely I mean there's no way around itYeah S-bomb will show you what external resources you're using but doesn't necessarily say that this chunk of code was written by Bobby the intern on a summer trip here or anything like that.
Transcript
Play full episode