(CS)²AI Online™ Seminar: ICS Supply Chains: SBOM Sharing Gets Interesting

Typ wydarzenia:
27.03.2024 (środa)

Software Bills of Materials (SBOMs) have become the default method of enunciating the contents of applications. To date SBOMs have been created in small volumes and typically only shared directly between software vendors and their customers. To facilitate the sharing of SBOM data across the pertinent operational areas of complex supply chains, a more sophisticated means of implementing controls has been necessary.

The public/private CISA SBOM Sharing Working Group has developed a taxonomy to describe the more complex movement of SBOMs needed to leverage this source of inventory information. In this session, the co-chair of this working group will explain the three Actors defined in the SBOM Sharing Roles and Considerations document published this month (March, 2024) on the CISA website.

An SBOM Author creates a given SBOM and sets the Discovery, Access, and Transport (see CISA SBOM Sharing Lifecycle publication, 2023) methods and permissions necessary to make this SBOM available. An SBOM Consumer creates the need to share a given SBOM and defines the Discovery, Access, and Transport they will accept. An SBOM Distributor is any entity which must respond to requirements to share SBOMs they did not create and are not directly using (think ISACs, integrators, service providers, ...) while ensuring the requirements of all parties are maintained.


An understanding of the considerations when acting as an SBOM Author, SBOM Distributor, or an SBOM Consumer and how these may affect your related duties and concerns.

Insight into the advantages and challenges of this new flow of intelligence.

Speaker: Chris Blask, VP Strategy, Cybeats, Chair of ICS-iSAC, Author, Speaker, Ponderer of Inevitability Curves, and CS2AI Founding Fellow


