Cloud Security Podcast by Google

EP116 SBOMs: A Step Towards a More Secure Software Supply Chain

10 snips
Apr 10, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

SBOMs for Vulnerability Management

  • SBOMs (Software Bill of Materials) list software components like ingredient labels on food.
  • They help security leaders manage vulnerabilities, like identifying Log4j's presence.
ANECDOTE

Past Resistance to Transparency

  • Initial resistance to food labeling mirrored some software vendors' concerns about SBOMs, citing IP or "secret sauce" protection.
  • Government mandates, like the US executive order, aim to overcome this by requiring SBOMs for federal software.
INSIGHT

SLSA: Software "Provenance"

  • Just as food processing matters, software build processes impact security.
  • SLSA (Supply-chain Levels for Software Artifacts) provides a framework similar to "provenance" or a recipe for building software securely.
Get the Snipd Podcast app to discover more snips from this episode
Get the app