news.mlab.sh
Back to the feed
threat-intel

US and Allies Update SBOM Guidance

Info
Summary

The US government, alongside 13 allied nations, has released updated guidance on Software Bill of Materials (SBOMs) to enhance software supply chain security and transparency. This revised guidance builds upon previous efforts and incorporates feedback to improve data quality and address evolving needs, particularly for AI systems and SaaS applications.

The US government, in collaboration with 13 allied countries, has published updated guidance regarding Software Bill of Materials (SBOMs). This document represents a significant step forward in bolstering software supply chain security and promoting a more transparent approach to software development and deployment. The guidance is intended to serve as a foundational element for organizations involved in producing, procuring, and utilizing software, enabling them to better understand the components within their environments and proactively manage associated risks.

The updated guidance builds on the 2021 SBOM Minimum Elements guidance and incorporates feedback received during a public comment period. It focuses on improving data quality and expanding the utility of SBOMs to encompass a wider range of use cases, including the increasing complexity of AI systems and Software-as-a-Service (SaaS) offerings. Several elements have been added, such as the Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version. Two elements, Access Control and Software Identification (SWID) Tags, were removed, while others were clarified and modified to improve data mapping, specifically the component name, which now allows for multiple entries.

This initiative reflects a broader trend of increased scrutiny and demand for software supply chain visibility, driven by advancements in SBOM tooling and a growing awareness of potential vulnerabilities. The guidance acknowledges that AI systems and SaaS applications may require additional elements beyond the core minimums. The release follows similar efforts by G7 nations to address the security implications of AI development and deployment.

Read the full article at SecurityWeek