U.S. Army Adopts SBOMs in Software Procurement and Modernization Efforts, Leveraging Open-Source Tools for Enterprise-Scale Analysis

 Large enterprises are increasingly requesting Software Bills of Materials (SBOMs), with suppliers like Splunk regularly providing them. Despite regulatory uncertainty, the U.S. Army has started incorporating SBOMs into procurement. Army Directive 2024-02 calls for modernizing software acquisition, and an August memo outlines SBOM policy, effective in late 2024. Jose Caseja from the Army discussed internal SBOM workflows and the use of open-source tools like Syft, Grype, Dependency-Track, and Bomber to analyze SBOM data and vulnerabilities during a CISA event.

https://www.techtarget.com/searchitoperations/feature/366611692/US-Army-Lockheed-Martin-detail-SBOM-progress

Comments

Popular posts from this blog

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Critical OpenSSH Flaws Enable MITM and DoS Attacks

MITRE ATT&CK v19 Redefines How Defenders Model Modern Threats