Skip to main content

SBOMs and the importance of inventory

Can a Software Bill of Materials (SBOM) provide organisations with better insight into their supply chains?

Nadezhda Buravleva via Getty Images

Software supply chains are big, complex, and are an enticing target for a cyber attack (as the high-profile SolarWinds compromise illustrated). This is why having a software inventory, knowing what it contains (and therefore knowing what you must secure) is such a vital security measure.

One tool that can help you do this is a Software Bill of Materials, or SBOM. An SBOM is an often-cited tool which lists the component parts and software dependencies of a software package, and is designed to help vendors and developers better understand the open source and third party components it may contain. This should be an exhaustive list which includes open-source libraries, proprietary software, and licensed dependencies. Some may also include the tools used to produce the software, along with other provenance information.

The NCSC recognises that SBOMs are being increasingly used in many settings. The White House’s 2021 Executive Order on Improving the Nation’s Cybersecurity put SBOMs in the limelight and made them mandatory if software is used in federal IT systems. In 2022, the EU proposed the Cyber Resilience Act (CRA), in which one of the specific goals is “To increase transparency into the range of software’s range of exploitable vulnerabilities and associated security elements”, with SBOMs referenced as a way to “provide those who manufacture, purchase, and operate software with information that enhances their understanding of the supply chain, which has multiple benefits, in particular it helps manufacturers and users to track known newly emerged vulnerabilities and cybersecurity risks.”

However, SBOMs have only become mainstream recently, and thus the tools are still maturing and an understanding of how to use them is still evolving. This blog discusses the importance of keeping track of your software inventory, how (and where) SBOMs can be used, and also points out their limitations.

It’s important to note that this blog is neither an endorsement nor a rejection of SBOM technologies. The value of any SBOM implementation will depend upon a number of factors, including your wider software development processes and practices, the experience of your staff, and your organisation’s risk appetite. Perhaps most importantly, the mere presence of a SBOM does not guarantee that a supply chain is secure, and is not the answer to resolving all your supply chain risks.

Note:

For detailed information about how to assess and gain confidence in your supply chain cyber security, please refer to the NCSC’s Supply Chain Guidance.






Written by

Harrison L Research Lead for Software Supply Chain Security