SBOMs, Beyond the Horizon
Fortress Information Security
Critical Supply Chain Cyber Security | Fortress. Absolutely Critical. www.fortressinfosec.com
In my last blog post I discussed some of the difficulties encountered with operationalizing SBOMs.? In this post I’ll discuss where I think SBOMs will go and the need behind this forecasted progress.
The Future
Where do SBOMs go from here? Professionally, I feel SBOMs are on the cusp of greatness. The current state of SBOM adoption is just a couple years outside of being a household name in cybersecurity parlance. If I gaze into my crystal ball, here’s what I see… or at the very least hope for:
Why? Greater vendor participation will result in greater access to quality SBOMs. Having vendors merely aware of their own dependencies fosters better development practices. I just got off a call with a vendor on behalf of a client who swore up and down that they didn’t utilize Zlib in their software. Our SBOM analysis was illuminating vulnerabilities for Zlib after we performed static analysis on their software. Well, it turns out they sort of were. While they weren’t directly using Zlib in their software they were using InstallShield to bundle their software which did have Zlib. This finding helped the vendor patch and fix the vulnerability in their product.
Why? Consumers of SBOM data need a way to cut through the noise. A single open-source software component can have dozens or even hundreds of vulnerabilities associated with it. Just because there are vulnerabilities associated with the software component doesn’t mean the parent product is vulnerable. VEX provides a way to ‘dismiss’ vulnerabilities as unaffected in a machine-readable format.
领英推荐
Why? If SBOMs are going to be used in the absence of a regulatory body shouting ‘thou shalt’, the experience can’t be painful. Additionally, for SBOMs to be useful, they need to be consumable in a concise and organized way. Most tools are already there, but they are all undergoing a final polish to capture all the use cases organizations have for SBOMs
In summary, I believe SBOMs are here already. They’ve been here and the technologies to support SBOMs have improved dramatically over the past 5-10 years. This doesn’t mean we at Fortress are done and prepared to coast. I still find SBOMs can be operationally prohibitive at times for organizations and I’m looking into the future to resolve these speed bumps when it comes to adoption. In the very near future, I believe SBOMs will become routine across industries (energy, healthcare, banking, automotive, etc.) even in the absence of regulatory requirements for them.