Posts

Showing posts with the label Supply Chain

SBOM Explained: Software Bill of Materials for Security+ and CySA+

A software bill of materials , or SBOM , is a formal, machine-readable inventory of every component inside a piece of software — the libraries, frameworks, and dependencies it is built from, including the ones its dependencies pull in. You cannot patch what you do not know you are running. An SBOM is the answer to "are we affected?" before it takes three days to find out. The case for it was made decisively by Log4Shell in December 2021. A critical vulnerability landed in Log4j, a logging library embedded so deeply in the Java ecosystem that most organizations genuinely could not tell whether they used it. Teams spent weeks grepping filesystems. Organizations with accurate SBOMs answered the question in minutes. That contrast is why SBOMs went from a niche supply-chain idea to a procurement requirement and, in the United States, a federal one under Executive Order 14028. What Is Actually In One An SBOM entry typically records, for every component: Name and version ...