Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

JC Herz and Steve Springett — SBOMs and software supply chain assurance

48 min12 januari 2021

Om avsnittet

Software bills of materials promise visibility into dependencies, but visibility alone does not create assurance. JC Herz and Steve Springett join Chris and Robert to explain what an SBOM contains, why machine-readable formats matter, and how CycloneDX and Dependency-Track help organizations reason about software composition. They compare automated inventories with spreadsheets and audits, examine the threats an SBOM can and cannot address, and discuss why regulation and supply-chain incidents pushed the topic into the spotlight. The conversation closes with adoption guidance, including how teams can connect SBOM data to vulnerability management and verification instead of treating it as another compliance artifact.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with JC Herz and Steve Springett:
JC Herz on LinkedIn
Steve Springett on LinkedIn
CycloneDX

Mentioned in this episode:
CycloneDX
Dependency-Track
National Vulnerability Database
The left-pad incident

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 SBOMs and software supply-chain assurance
01:47 Introducing the guests and the problem
06:51 Steve Springett and the CycloneDX ecosystem
10:00 What an SBOM contains
17:45 CMMC, audits, and assurance requirements
20:38 Understanding software composition
22:34 Why spreadsheets do not scale
25:00 Different consumers need different SBOM views
27:00 The threats SBOMs can help address
33:30 Why the industry is paying attention now
39:00 When and where to generate an SBOM
41:00 Adoption through OWASP and SCVS
44:46 Practical takeaways

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.