News

CISA Calls for Enhanced Transparency in US Software Supply Chain

October 17, 2024 2 min read
author Anamika Mishra, Sub Editor
The US Cybersecurity and Infrastructure Security Agency (CISA) has released the third edition of Framing Software Component Transparency, a crucial document aimed at improving the understanding and implementation of the Software Bill of Materials (SBOM). This latest version, crafted by CISA's SBOM Tooling & Implementation Working Group, provides updated guidelines on creating SBOMs and identifying software components. These enhancements address the growing challenges organizations face in achieving transparency and security within software supply chains. The new edition builds upon the 2021 version, outlining essential SBOM attributes categorized into three tiers: minimum expectations, recommended practices, and aspirational goals. This structured approach offers organizations a clear framework for managing their software components effectively. CISA emphasizes that merely providing basic information in an SBOM is inadequate for all scenarios. As the use of SBOMs expands, organizations must adopt more sophisticated practices for sharing and managing this critical data. This is increasingly important as enterprises confront operational and supply chain security challenges stemming from limited visibility into their deployed software

The only supply chain registration you need

Unrivaled context behind every news and article for free.

Register
logo

Subscribe to Our Newsletter

The week’s best stories, handpicked by JOSC editors in your inbox every week.

Stay informed with exclusive content