Laurie Williams
Laurie_williams@ncsu.edu
1
Software Bill of Materials
https://ntia.gov/files/ntia/publications/ntia_sbom_energy_jan2021overview_0.pdf
Executive Order 14028
2
Photo by Tabrez Syed on Unsplash
Software Bill of Materials (SBOM) Generation
From EO 14028
What is a Software Bill of Materials (SBOM)
SBOM Standards
What’s a SBOM for?
6
Yingyaipumi/stock.adobe.com
Seventyfour i/stock.adobe.com
A good SBOM should allow organizations to answer questions like, “Am I vulnerable to the CVE-2022-22965 (Spring4Shell) vulnerability?”
SBOM Formats
Exercise
Any concerns with/reaction to SBOM?
Open-source SBOM Generation Tools
https://www.wiz.io/academy/top-open-source-sbom-tools
Vulnerability Exploitability eXchange (VEX)
https://www.cisa.gov/sites/default/files/2023-01/VEX_Use_Cases_Aprill2022.pdf
Vulnerability Exploitability eXchange (VEX)
https://www.cisa.gov/sites/default/files/2023-01/VEX_Use_Cases_Aprill2022.pdf
Any concerns with/reaction to VEX?
Summary