Does your business need a software bill of materials? An SBOM helps firms to regain control of the supply chain At the end of 2021, a now infamous vulnerability was found in the Apache Log4j open-source logging library. It led to a race against time, with teams struggling to identify which apps and services were affected and apply the patch before attackers could exploit the bug. As the risk of similar software supply chain threats multiplies, a software bill of materials (SBOM) can help. Essentially an inventory of open source and third party components, an SBOM is now part of regulations including the US Executive Order on Cybersecurity, the EU Cyber Resilience Act (CRA) and the EU Network and Information Systems 2 Directive (NIS2). How do SBOMs work, and does your business need one? Why firms need an SBOM Most modern applications include open source and third party components. As a result, a large share of software risk comes from dependencies that teams did not write themselves. “When a serious issue like Log4j appears, the first question is simple: Where are we exposed?” says Ilkka Turunen, field CTO at Sonatype. “If you cannot answer this question quickly, you have a real problem.” Log4j is “the prime example of why SBOMs can be indispensable”, says Dana Simberkoff, chief risk, privacy and information security officer at AvePoint. “Because the library is very broadly used in consumer and business-facing software applications, the attack on Log4j had catastrophic consequences for a wide range of applications across regions and sectors.” An SBOM might have prevented the worst effects of the attack by allowing IT professionals to more easily expose and patch the vulnerability that triggered it, according to Simberkoff. Sign up today and you will receive a free copy of our Future Focus 2025 report
Does your business need a software bill of materials? | IT Pro
Read the original article
itpro.com →