

EP116 SBOMs: A Step Towards a More Secure Software Supply Chain
10 snips Apr 10, 2023
AI Snips
Chapters
Transcript
Episode notes
SBOMs for Vulnerability Management
- SBOMs (Software Bill of Materials) list software components like ingredient labels on food.
- They help security leaders manage vulnerabilities, like identifying Log4j's presence.
Past Resistance to Transparency
- Initial resistance to food labeling mirrored some software vendors' concerns about SBOMs, citing IP or "secret sauce" protection.
- Government mandates, like the US executive order, aim to overcome this by requiring SBOMs for federal software.
SLSA: Software "Provenance"
- Just as food processing matters, software build processes impact security.
- SLSA (Supply-chain Levels for Software Artifacts) provides a framework similar to "provenance" or a recipe for building software securely.