US and Allies Update SBOM Guidance
Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM).
Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year.
An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments.
In this regard, the updated minimum elements for an SBOM (PDF) guidance provides a baseline of the technologies and practices expected to be included in an SBOM.
“Organizations that produce, procure, and operate software can use SBOM data to better understand their software supply chain. Increased software supply chain visibility can...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE