US and Allies Update SBOM Guidance
Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM).
Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year.
An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments.
In this regard, the updated minimum elements for an SBOM (PDF) guidance provides a baseline of the technologies and practices expected to be included in an SBOM.
“Organizations that produce, procure, and operate software can use SBOM data to better understand their software supply chain. Increased software supply chain visibility can drive risk management decisions, including addressing known and newly discovered vulnerabilities and risks,” the guidance reads.
The updated document preserves the core principles of the 2021 SBOM Minimum Elements while reflecting current SBOM needs. It improves data quality, supports a broader range of use cases and applications, introduces new elements, removes others, and updates descriptions for improved clarity.
New additions include the Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version elements.
While only two elements were removed from the updated guidance, namely Access Control and Software Identification (SWID) Tags, multiple elements were replaced, others were clarified or rewritten, and others were modified to improve data mapping, such as the component name, which now allows multiple entries.
“SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs. These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021,” the guidance reads.
According to the authoring agencies, while the document applies to all software, some types of software, such as AI systems and SaaS, may require additional elements. In May, government agencies from Group of Seven (G7) countries released SBOM guidance for AI.
Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure
Related: Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data
Related: US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
Related: How to Conduct a Successful Audit of AI-Driven Software Development