SBOMs – Software Supply Chain Security’s Future or Fantasy?
Summary
Eighteen months later, in December 2022, a big tech lobbying group representing Amazon, Apple, Cisco, Google, IBM, Intel, Mastercard, Meta, Microsoft, Samsung, Siemens, Verisign and more, wrote to the OMB: “We ask that OMB discourage agencies from requiring artifacts [SBOMs} until there is a greater understanding of how they ought to be provided and until agencies are ready to consume the artifacts that they request.” If after eighteen months – and we’re still in the same position today – meaningful use of SBOMs is unachievable, we need to ask what needs to be done to fulfill Biden’s executive order. It describes its role as “facilitating community engagement, development, and progress, with a focus on scaling and operationalization, as well as tools, new technologies, and new use cases.” In April 2023, CISA released three SBOM-related documents. But in more detail, it says, “Responsibility must be placed on the stakeholders most capable of taking action to prevent bad outcomes, not on the end-users that often bear the consequences of insecure software nor on the open source developer of a component…” (our emphasis). Basically, you either need to have it be the ‘easy button’ and be available without any or much work, or explicitly require it (which will then cause the first one to happen, as people will want it done by default).” Pedro Fortuna, CTO and co-founder of Jscrambler, has a solution. “But there’s no silver bullet in supply chain security, nor any part of cybersecurity in general.” So, in answer to our original question, we likely won’t know for another decade whether the SBOM will become a success or remain a fantasy.