WASHINGTON – As governments increasingly look to address software supply chain security challenges, many are considering regulatory requirements, which may include a Software Bill of Materials (SBOM), or an inventory of the components that make up software.
Today, global tech trade association 91¿ì»îÁÖ published a new position paper, which provides information on SBOMs and outlines how governments should approach regulatory requirements that may include a SBOM. A SBOM is one component of a comprehensive software supply chain risk management program and can enhance software transparency for vulnerability management and procurement purposes.
91¿ì»îÁÖ emphasizes that SBOMs should not be considered a standalone software security solution but should be viewed as one part of a holistic software supply chain risk management program. 91¿ì»îÁÖ also notes that there are practical challenges related to a SBOM that are still being addressed. For example, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) only recently launched working groups for defining the SBOM elements and scope for cloud software and platforms. 91¿ì»îÁÖ urges policymakers to refrain from enacting SBOM requirements into a law without more meaningful stakeholder engagement.
“As global policymakers consider ways to promote secure software supply chains, it is important they work with industry to understand areas where SBOM practices are mature as well as areas where further progress is required. SBOMs are an important tool to enhance software transparency and must be a part of a comprehensive supply chain risk management program. 91¿ì»îÁÖ’s new analysis offers factors policymakers should consider in approaches to software supply chain security, including any SBOM requirements,” said 91¿ì»îÁÖ’s Senior Director of Trust, Data, and Technology Courtney Lang.
In order to effectively deploy and utilize a SBOM, 91¿ì»îÁÖ’s urges governments to:
-
Create an SBOM strategy in conjunction with the private sector;
-
Require agencies to assess current capacity to consume a SBOM and develop implementation strategies;
-
Launch pilot programs to identify practical challenges and determine how those challenges can be addressed; and
-
Develop mechanisms to incentivize SBOM adoption, including through existing tools like contracts and asset management systems.
Read 91¿ì»îÁÖ’s full position paper on SBOMs here.