FW: CISA SBOM update
FYI: Update an update today from Allan Friedman re: CISA SBOM activities – see email below.
NOTE from Allan: As a reminder, CISA facilitates these open discussions, but the participants shape the agenda. These are also expressly not a forum for discussing USG policy, or offering any kind of advice to CISA.
CISA does have sanctioned activities that touch on SBOM matters under the ICT_SCRM Task Force, which are producing Guidance Documents issued by CISA:
ICT_SCRM Task Force work streams and other information, i.e., task force membership is also available here; the Small and Medium Business Guidebook was published in January 2023: https://www.cisa.gov/resources-tools/groups/ict-supply-chain-risk-management-task-force
I work on three ICT_SCRM Task Force work streams: Small and Medium-sized Businesses Working Group Software Assurance Working Group Product Marketing Working Group
Thanks,
Dick Brooks
Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council – A Public-Private Partnership
Never trust software, always verify and report! ™ http://www.reliableenergyanalytics.com Email: dick@... Tel: +1 978-696-1788
From: Friedman, Allan <allan.friedman@...>
Sent: Tuesday, March 14, 2023 10:39 AM To: Murphy, Justin <justin.murphy@...>; DOSCHER, MEGAN <MEGAN.DOSCHER@...>; SBOM <SBOM@...> Cc: STODDARD, JEREMIAH (CTR) <JEREMIAH.STODDARD@...> Subject: CISA SBOM update
Dear SBOM community,
Over the last few months, the five community-led workstreams on SBOM have been making progress. Below is a quick summary of the focuses, and current activities of each group.
As a reminder, CISA facilitates these open discussions, but the participants shape the agenda. These are also expressly not a forum for discussing USG policy, or offering any kind of advice to CISA.
Please don’t hesitate to reach out if you have any questions. allan
VEX Monday, 10 AM ET – 11 AM ET (email SBOM@... for calendar invite) This workstream defines and refines the Vulnerability Exploitability eXchange (VEX) model, which allows attestations on whether a product is affected or not affected by a given vulnerability, and characterize VEX use cases and operations. Current activities:
Sharing & Exchanging SBOMs Monday, 12 PM ET – 1 PM ET (email SBOM@... for calendar invite) The Sharing and Exchanging workstream focuses on the topic of moving SBOMs and related metadata across the software supply chain. The working group discusses how to enable discovery and access, while underscoring the importance of solution interoperability. Current activities:
On-Ramps & Adoption Tuesday, 12 PM ET – 1 PM ET (email SBOM@... for calendar invite) The On-Ramps and Adoption workstream focuses on promoting education and awareness to help lower the costs and complexities of Adoption, allowing newer or less mature organizations to provide, request, and use SBOMs to secure and understand their organization’s risk. The goal is to meet people where they are, remove barriers, reduce friction, and accelerate adoption. The workstream may define further use cases for SBOM. The final workstream focus is to coordinate efforts across all new and existing SBOM-related workstreams to help in communications as well as help to avoid substantive overlap.
Current activities include:
Cloud & Online Applications Wednesday, 3 PM ET – 4 PM ET (email SBOM@... for calendar invite) The Cloud and Online Applications workstream focuses on integrating current understanding around SBOM into the context of online applications and distributed, on-demand infrastructure. Most of the existing discussion around SBOM, particularly around SBOM use cases, has focused on on-premise software. Online, cloud-based applications comprise a large and growing segment of the software ecosystem. It will be important to integrate the current understanding of SBOM with emergent advances in cloud-native technologies to tell better stories about SBOM use cases for cloud and understand how this will be handled across organizational boundaries. Current activities include:
Tooling & Implementation Thursday, 3 PM ET – 4 PM ET (email SBOM@... for calendar invite) The Tooling and Implementation workstream focuses on opportunities and challenges for automating the SBOM ecosystem. This ecosystem will be driven by a range of accessible and constructive tools and enabling applications, both open source and proprietary. This work will potentially enhance existing SBOM data with further implementation details, encourage interoperability, and foster the advancement and efficiency of the tooling marketplace. Current activities include:
You are receiving this email because of interest expressed in CISA’s SBOM work. To subscribe or unsubscribe, please contact SBOM@...
|
|