The Government’s Software Bill of Materials (SBOM) Mandate Is Part of a Bigger Cybersecurity Picture
Summary
Walt Szablowski, Founder and Executive Chairman of Eracent, which has provided complete visibility into its large enterprise clients’ networks for over two decades, observes, “SBOMs are meaningless unless they are part of a larger strategy that identifies risks and vulnerabilities across the software supply chain management system.” The National Telecommunications and Information Administration (NTIA) defines a Software Bill of Materials as “a complete, formally structured list of components, libraries, and modules that are required to build a given piece of software and the supply chain relationships between them.”(4) The U.S. is especially vulnerable to cyberattacks because much of its infrastructure is controlled by private companies who may not be equipped with the level of security necessary to thwart an attack. (5) The key benefit of SBOMs is that they enable organizations to identify whether any of the components that make up a software application may have a vulnerability that can create a security risk. Second, they must be able to establish an automated, proactive process to stay on top of SBOM-related activity and all of the unique mitigation options and processes for each component or software application.” Eracent’s cutting-edge Intelligent Cybersecurity Platform (ICSP)™ Cyber Supply Chain Risk Management™ (C-SCRM) module is unique in that it supports both of these aspects to provide an additional, critical level of protection to minimize software-based security risks. Eracent helps its customers meet the challenges of managing IT network assets, software licenses, and cybersecurity in today’s complex and evolving IT environments. Eracent’s enterprise clients save significantly on their annual software spend, reduce their audit and security risks, and establish more efficient asset management processes.