EPISODE · Jan 12, 2021 · 48 MIN
JC Herz and Steve Springett — SBOMs and software supply chain assurance
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Software bills of materials promise visibility into dependencies, but visibility alone does not create assurance. JC Herz and Steve Springett join Chris and Robert to explain what an SBOM contains, why machine-readable formats matter, and how CycloneDX and Dependency-Track help organizations reason about software composition. They compare automated inventories with spreadsheets and audits, examine the threats an SBOM can and cannot address, and discuss why regulation and supply-chain incidents pushed the topic into the spotlight. The conversation closes with adoption guidance, including how teams can connect SBOM data to vulnerability management and verification instead of treating it as another compliance artifact.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with JC Herz and Steve Springett:→ JC Herz on LinkedIn→ Steve Springett on LinkedIn→ CycloneDXMentioned in this episode:→ CycloneDX→ Dependency-Track→ National Vulnerability Database→ The left-pad incidentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 SBOMs and software supply-chain assurance01:47 Introducing the guests and the problem06:51 Steve Springett and the CycloneDX ecosystem10:00 What an SBOM contains17:45 CMMC, audits, and assurance requirements20:38 Understanding software composition22:34 Why spreadsheets do not scale25:00 Different consumers need different SBOM views27:00 The threats SBOMs can help address33:30 Why the industry is paying attention now39:00 When and where to generate an SBOM41:00 Adoption through OWASP and SCVS44:46 Practical takeaways
Embed this episode
What this episode covers
Software bills of materials promise visibility into dependencies, but visibility alone does not create assurance. JC Herz and Steve Springett join Chris and Robert to explain what an SBOM contains, why machine-readable formats matter, and how CycloneDX and Dependency-Track help organizations reason about software composition. They compare automated inventories with spreadsheets and audits, examine the threats an SBOM can and cannot address, and discuss why regulation and supply-chain incident...
Ready to play
JC Herz and Steve Springett — SBOMs and software supply chain assurance
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.