JC Herz and Steve Springett — SBOMs and software supply chain assurance episode artwork

EPISODE · Jan 12, 2021 · 48 MIN

JC Herz and Steve Springett — SBOMs and software supply chain assurance

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Software bills of materials promise visibility into dependencies, but visibility alone does not create assurance. JC Herz and Steve Springett join Chris and Robert to explain what an SBOM contains, why machine-readable formats matter, and how CycloneDX and Dependency-Track help organizations reason about software composition. They compare automated inventories with spreadsheets and audits, examine the threats an SBOM can and cannot address, and discuss why regulation and supply-chain incidents pushed the topic into the spotlight. The conversation closes with adoption guidance, including how teams can connect SBOM data to vulnerability management and verification instead of treating it as another compliance artifact.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with JC Herz and Steve Springett:→ JC Herz on LinkedIn→ Steve Springett on LinkedIn→ CycloneDXMentioned in this episode:→ CycloneDX→ Dependency-Track→ National Vulnerability Database→ The left-pad incidentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 SBOMs and software supply-chain assurance01:47 Introducing the guests and the problem06:51 Steve Springett and the CycloneDX ecosystem10:00 What an SBOM contains17:45 CMMC, audits, and assurance requirements20:38 Understanding software composition22:34 Why spreadsheets do not scale25:00 Different consumers need different SBOM views27:00 The threats SBOMs can help address33:30 Why the industry is paying attention now39:00 When and where to generate an SBOM41:00 Adoption through OWASP and SCVS44:46 Practical takeaways

Episode metadata supplied by the publisher feed · Published Jan 12, 2021

Embed this episode

Software bills of materials promise visibility into dependencies, but visibility alone does not create assurance. JC Herz and Steve Springett join Chris and Robert to explain what an SBOM contains, why machine-readable formats matter, and how CycloneDX and Dependency-Track help organizations reason about software composition. They compare automated inventories with spreadsheets and audits, examine the threats an SBOM can and cannot address, and discuss why regulation and supply-chain incident...

Distinct summary based on available episode metadata or transcript content.

Ready to play

JC Herz and Steve Springett — SBOMs and software supply chain assurance

0:00 48:10

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 12, 2021.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!