Unraveling SBOM Challenges: AI, Transparency and Policy Perspectives in Software Security
Unraveling SBOM Challenges: AI, Transparency and Policy Perspectives in Software Security

Unraveling SBOM Challenges: AI, Transparency and Policy Perspectives in Software Security

Khurlvin_Kay

42 min
News
Play

Description

<p>Meet the man on a mission to make software bill of materials (SBOMs) boring. In this So What? episode, Tracy Bannon and Carolyn Ford sit down with Allan Friedman the Senior Advisor and Strategist at the Cybersecurity and Infrastructure Security Agency (CISA). Allan tells us about how he is working to change how all software on the planet is made and sold, no big deal right? Join us as we dive into the world of SBOMs, xBoMs, and Secure by Design.</p><h2>Key Topics</h2><ul><li>03:59 Track open source licenses, establish shared vision.</li><li>08:47 Discussing US government requirements, diversity in software.</li><li>12:07 Framework helps organizations with secure software development.</li><li>13:49 Organizations unaffected, prepare for impending software changes.</li><li>17:40 Concerns about sharing software with potential security risks.</li><li>20:59 Concerns about network security and regulatory pushback.</li><li>24:14 Enhanced security measures save thousands of hours.</li><li>27:53 Applying AI and data bombs in conversation.</li><li>32:38 Discusses the importance of SBOM in cybersecurity.</li><li>36:29 Rewriting global code is a complex task.</li><li>39:39 At RSA, little focus on secure design.</li><li>41:53 Organization's need for SBOM, call to action.</li><li>43:55 Cooking for diverse family, diverse food requirements.</li></ul><br/><h2>Challenges and Implementation of SBOMs</h2><h3>Self-Attestation for SBOMs</h3><p>Allan Friedman explained that there is currently a self-attestation model for SBOMs, where companies can sign a form stating that they have implemented SBOMs, rather than providing the actual SBOM data. This allows flexibility for organizations that are not yet ready to fully comply. However, it means buyers have to trust the attestation rather than seeing the SBOM details directly.</p><blockquote><strong><em>Secure Software Development Model Compliance: </em></strong><em>"The challenge there is turning the framework back into a compliance model. Because, again, at the end of the day, everyon

Uploader

mia_dot

mia_dot

Unraveling SBOM Challenges: AI, Transparency and Policy Perspectives in Software Security - Listen Free | WowFM