Council Post: How SBOMs Help Uncover Vulnerabilities In Enterprise Applications

  • 📰 ForbesTech
  • ⏱ Reading Time:
  • 63 sec. here
  • 3 min. at publisher
  • 📊 Quality Score:
  • News: 29%
  • Publisher: 59%

Technology Technology Headlines News

Technology Technology Latest News,Technology Technology Headlines

The software bill of materials (SBOM) has become the go-to solution to identify the threats of software vulnerabilities and software supply chain attacks.

Organizations like to maintain an inventory of the assets in the software they develop, but it can be a black box when it comes to the software they buy. Having an inventory of your software inventory used to mean asking suppliers to self-attest if they were following secure development practices such as having third parties evaluate and test the software.

When news of Log4j first surfaced, many enterprises spent weeks scouring their networks to determine whether they were exposed to the vulnerability—and if it was being actively exploited in their environment. With an inventory of their software artifacts provided by SBOMs, the assessment would have taken minutes not weeks. The mean time to detection and response window, a critical factor in threat mitigation, would have been dramatically reduced.

SBOMs are also an effective procurement tool, allowing organizations to assess the risk of new COTS applications they want to deploy by identifying hidden dependencies such as OpenSSL. Procurement practices are adopting more shift-left principles and bringing security into the process of software selection, much like software engineers are incorporating security into the software development process.

Applying the same discipline to legacy apps as COTS software by generating SBOMs for them can go a long way to address the security and risk management baked into them. A single standard provides visibility and control.Overall, SBOMs are crucial for improving software security, ensuring compliance and managing vulnerabilities throughout the software development life cycle.

 

Thank you for your comment. Your comment will be published after being reviewed.
Please try again later.
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

 /  🏆 318. in TECHNOLOGY

Technology Technology Latest News, Technology Technology Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

Council Post: In The Age Of AI, Everything Is An APIWe stand at the crossroads of a monumental technological paradigm shift. As AI continues to advance, APIs are evolving in parallel to unlock and amplify this potential.
Source: ForbesTech - 🏆 318. / 59 Read more »

Council Post: Beyond Algorithms: The AI Era In Investment FinTechThe ethical ramifications of AI in finance extend beyond just algorithmic biases.
Source: ForbesTech - 🏆 318. / 59 Read more »

Council Post: Four Tips For Developing Successful MarTech SolutionsDon't pick the technology before you learn enough about your prospective customers and their business needs.
Source: ForbesTech - 🏆 318. / 59 Read more »