SEP 01, 2022 | US
Software Industry Leader BSA Raises Cautionary Notes on Codifying Use of SBOMs
Inside Cybersecurity, September 1, 2022
By Charlie Mitchell
Policymakers should slow the “rush to codify” a requirement for vendors to produce a Software Bill of Materials, according to BSA | The Software Alliance, which says SBOMs can be a useful tool for improving supply chain cybersecurity but won’t provide “a silver bullet” and still need more work before they are mandated in contracts.
“Too many policymakers incorrectly assume that 1) SBOMs and supporting materials are ready for use, if policymakers incentivize a vendor to provide one; 2) organizations, including US Government agencies, are prepared to effectively use SBOMs they receive from vendors; and 3) an SBOM would solve a majority, if not all, of today’s cybersecurity challenges,” BSA policy director Henry Young said in a blog post on Wednesday.
Original Posting: https://insidecybersecurity.com/share/13845
ABOUT BSA
The Business Software Alliance (www.bsa.org) is the global trade association of the enterprise software industry, representing companies that are leaders in artificial intelligence, cybersecurity, cloud computing, and other cutting-edge technologies. We work in over 20 markets in the US, Europe, and Asia, advocating for policies that build trust in technology so that every industry sector and the public can benefit from innovation. BSA also supports its members and their customers by raising awareness of the risks of unlicensed software use and the benefits of software asset management, driving license compliance and software adoption around the world through sound IT procurement.