This CISA draft refines the foundational elements of a Software Bill of Materials (SBOM), helping agencies and organizations understand and manage the software components they use. It updates the 2021 baseline with new fields like component hash, license, and tool name, and clarifies practices for cloud, AI, and automation. By standardizing SBOM data and processes, it enables faster risk identification, stronger software supply chain security, and improved response to vulnerabilities.
Format: |
|
Topics: | |
Website: | Visit Publisher Website |
Publisher: | Cybersecurity and Infrastructure Security Agency (CISA) |
Published: | August 1, 2025 |
License: | Public Domain |