The Governments Software Transparency Journey Moves from Plan to Practice
Summary
Having piloted the Commerce Department’s effort to shape the definition and implementation of a software bill of materials—likened to an ingredients list of components in complicated supply chains—Allan Friedman will now play an instrumental role scaling and operationalizing the concept from his new perch at the Cybersecurity and Infrastructure Security Agency. From within the vulnerability management unit of CISA’s cybersecurity division, he is positioned to influence coming guidelines and potential procurement regulations under a May 12 executive order requiring agencies to ask their suppliers to provide so-called SBOMs. During his years as director of cybersecurity initiatives at the Commerce Department’s National Telecommunications and Information Administration, Friedman worked to bring software vendors, customers and other interested parties together on baseline elements for a standard SBOM. In line with the executive order, Friedman and his team at NTIA in July issued “minimum elements of a software bill of materials,” a step toward creating a potential federal benchmark and market standard. A few other stakeholders, some from the software manufacturer side, and the high-profile vulnerability disclosure and management entrepreneur Katie Moussouris, have argued that the SBOM requirement could end up creating work that federal employees aren’t resourced to do.