SBOMs (software bills of materials) have become an essential tool in securing software supply chains. But what’s the right way to use them? In this episode, Matt Rose explains how software publishers need to shift up their SBOMs, so that they showcase the entire threat landscape posed to software supply chains.
Keep learning
-Related: SBOMs: Your Software Ingredient List
-Report: How and Why NIST is Driving SBOM Evolution
-Report: The State of Supply Chain Security
Episode Transcript
MATT ROSE: Hi everyone. Welcome back to another episode of ReversingGlass. I'm Matt Rose, Field CISO at ReversingLabs and your host for this glass board series. Today's episode, as you can see, it's always across the top, is Shift Up Your SBOM. This is a continuation of my previous episode.
That talked about shift up your software supply chain security initiative's programs. So first of all, let's level set: SBOM or software bill of materials is a hot topic. Everybody's talking about this self attestation, having everything in the piece of software that you're selling or your allowing your customers to use.
The two main formats that I like to talk about are Cyclone DX and SPDX, a little squeaky today. So Cyclone DX stands for data exchange and SPDX is software package data exchange. These are both formats that are recognized in the industry for consistency for a way to deliver information that's expected, if you will.
But the thing is a lot of organizations are talking about SBOMs and they're creating their own format. One of the biggest things is thinking about using an SBOM for just a component. And this is where you gotta shift up your SBOM. SBOM associated with software supply chain security has to be complete.
It has to be holistic. So the way I like to think about this is, why don't we think about an SBOM or a proper SBOM as like a satellite above the earth looking down, seeing the whole side of the earth, that it's actually focused on, a whole continent, a whole country. So thinking about an SBOM to be effective has to be in one of these two formats or other recognized formats and has to have the whole picture, not just a piece of the puzzle.
The one of the problems that people do is they, I got a prop here for you today, they look at SBOMs or the information in an SBOM through a very finite lens. So here I am, I have my binoculars. If I'm looking through my binoculars, you like my prop today, looking through my binoculars, I'm gonna see something very small.
Field CISO at ReversingLabs. Matt Rose has an extensive background in application security, object-oriented programming, multi-tier architecture design and implementation, and internet/intranet development. His areas of expertise include Application Security, SAST, DAST, IAST, SCA, DevSecOps, and Threat Modeling. Matt is an accomplished public speaker and has been quoted in 50+ AST industry media publications.



