U.S. Army Adopts SBOMs in Software Procurement and Modernization Efforts, Leveraging Open-Source Tools for Enterprise-Scale Analysis

 Large enterprises are increasingly requesting Software Bills of Materials (SBOMs), with suppliers like Splunk regularly providing them. Despite regulatory uncertainty, the U.S. Army has started incorporating SBOMs into procurement. Army Directive 2024-02 calls for modernizing software acquisition, and an August memo outlines SBOM policy, effective in late 2024. Jose Caseja from the Army discussed internal SBOM workflows and the use of open-source tools like Syft, Grype, Dependency-Track, and Bomber to analyze SBOM data and vulnerabilities during a CISA event.

https://www.techtarget.com/searchitoperations/feature/366611692/US-Army-Lockheed-Martin-detail-SBOM-progress

Comments

Popular posts from this blog

Endor Labs Announces Integrated SAST Offerings

The Hidden Cost of DevSecOps: Time and Financial Burden of Security on Developers

OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features