Dick Brooks



               Minimal SBOM elements specified by NTIA for Executive Order (EO) 14028 do not include license data element requirements (see attached). The EO and the NTIA SBOM minimal elements focus on Cyber risk, i.e. C-SCRM, whereas license management is a Legal/Financial risk.


The use of SBOM for license legal risk management is indeed a good practice, but it is not required to satisfy NTIA minimal SBOM requirements for EO 14028.



From: spdx@... <spdx@...> On Behalf Of Phil Odence via
Sent: Tuesday, September 14, 2021 11:53 AM
To: spdx@...
Subject: Re: [spdx] SPDX Goes ISO


Thanks, Matija. Absolutely not just license compliance. Security too is a big driver and an important part/direction of SPDX.


From: spdx@... <spdx@...> on behalf of Matija Šuklje <matija@...>
Date: Tuesday, September 14, 2021 at 10:31 AM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX Goes ISO


This is indeed a massive step for the software world, and hopefully not just
in terms of license compliance!

hip hip hurrah!
gsm:    tel:+386.41.849.552
xmpp:   matija.suklje@...
sip:    matija_suklje@...

Join { to automatically receive all group messages.