Whats in your software? Federal initiative targets frequently overlooked electric utility vulnerabilities
Summary
Supply chain compromises, as the SolarWinds hack demonstrated, are more likely to come on the software side where cyber criminals could potentially gain access to critical infrastructure through vendor and manufacturer systems. "As a purchaser, you want to know what you are getting, and this tool could help entities identify product vulnerabilities that arent readily apparent, down to the software assembly and subset component levels," he said. An SBOM is also the first step for a company that makes or ships software to take ownership of their supply chain, said Allan Friedman, director of cybersecurity initiatives at NTIA. "We find new vulnerabilities every few months that widely affect a lot of software and embedded components that are really deployed everywhere in our ecosystem — especially in the energy world." It is primarily a chicken and egg problem — software developers must make SBOMs available before companies can use them in procurement and vulnerability tracking, but they wont be available unless customers ask.