The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international cybersecurity authorities have issued joint guidance updating the minimum elements of a Software Bill of Materials, or SBOM.

An SBOM is a detailed list of software components, including open-source libraries and hidden dependencies, along with the creators or vendors tied to those components. The new guidance replaces a 2021 document from the National Telecommunications and Information Administration (NTIA) on SBOM minimum elements.

The agencies said the update reflects changes in how organizations create and use SBOMs. "SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs", wrote the authoring agencies. "These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021."

Software supply chains can be large and complex, and vendors may be slow to release patches when vulnerabilities affect third-party components. According to the article, cybercriminals target software supply chains because they may have time to exploit vulnerabilities before patches are released. The source also said that while staying current with vendor patches is important, applying those patches alone does not guarantee software is secure.

If users obtain an SBOM from a software vendor, they can identify vulnerable or risky components before vendors release patches, allowing them to put temporary protections in place against software supply chain attacks.

What changed in the guidance

The latest guidance applies to all software solutions, though the authoring agencies said some types of software may need additional requirements, including AI-based software systems and software-as-a-service solutions in cloud environments.

The update adds ten data fields, revises eight components to clarify scope and specify expectations, and makes five minor updates to improve information quality and align the guidance with recent technical developments.

The agencies recommend that organizations use the guidance to confirm their SBOMs meet the minimum requirements and then evaluate each software solution to decide whether additional work is needed to improve software transparency.

The guidance is intended for organizations that produce, procure, or operate software, with the goal of helping them better understand their software components and supply chains and make more risk-informed decisions.

Read the source