U.S. Army Adopts SBOMs in Software Procurement and Modernization Efforts, Leveraging Open-Source Tools for Enterprise-Scale Analysis

 Large enterprises are increasingly requesting Software Bills of Materials (SBOMs), with suppliers like Splunk regularly providing them. Despite regulatory uncertainty, the U.S. Army has started incorporating SBOMs into procurement. Army Directive 2024-02 calls for modernizing software acquisition, and an August memo outlines SBOM policy, effective in late 2024. Jose Caseja from the Army discussed internal SBOM workflows and the use of open-source tools like Syft, Grype, Dependency-Track, and Bomber to analyze SBOM data and vulnerabilities during a CISA event.

https://www.techtarget.com/searchitoperations/feature/366611692/US-Army-Lockheed-Martin-detail-SBOM-progress

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines