What’s in the box: Software Bill of Materials for Devices

No ratings

Presented at INTERSCT. 2020 by

Devices are often seen as opaque, but we need better insight into the software components that make up the embedded systems on which we depend. This talk will present the emerging industry consensus around a “software bill of materials” that provides transparency around the underlying software components that are used to build modern, software-based devices. This “SBOM” can help developers deliver a more secure product, help buyers understand what they are acquiring, and operators understand the risks of what is on their networks over time. Transparency into the software supply chain further enables a host of further use cases around supply chain risk management and software assurance.