Listen "Leveraging Software Bill of Materials Practices for Risk Reduction"
Episode Synopsis
A Software Bill of Materials (SBOM) is a comprehensive list of software components involved in the development of a software product. While recently gaining attention in the context of security, SBOMs have limited value unless properly integrated into effective cyber risk management processes and practices. The SEI SBOM Framework compiles a set of leading practices for building an SBOM and using it to support risk reduction. The SEI SBOM Framework provides a roadmap for managing vulnerabilities and risks in third-party software, including commercial-off-the-shelf (COTS) software, government-off-the-shelf (GOTS) software, and open-source software (OSS). A set of use cases informed the identification of SBOM practices, including building an SBOM and using it to manage risks to software intensive systems. These foundational practices were augmented using key security management concepts, such as the need to address requirements, planning and preparation, infrastructure, and organizational support. In this webcast, Charles Wallen, Carol Woody, and Michael Bandor discuss how organizations can connect SBOMs to acquisition and development to support improved system and software assurance.
More episodes of the podcast Software Engineering Institute (SEI) Webcast Series
5 Essential Questions for Implementing the Software Acquisition Pathway and the Tools to Tackle Them
23/10/2025
Q-Day Countdown: Are You Prepared?
15/10/2025
Using LLMs to Evaluate Code
02/10/2025
Identifying AI Talent for the DoD Workforce
18/07/2025
Model Your Way to Better Cybersecurity
10/07/2025
DevSecOps: See, Use, Succeed
27/06/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.