-
Notifications
You must be signed in to change notification settings - Fork 37
Open
Description
During the meeting on 2024-03-12 a topic came up about how we could work together with other groups, especially government groups, to amplify what we are all doing. The notes from the meeting are below
Amplifying SBOM Everywhere Guidance through CISA SBOM Workstreams
- We should try to do this, yes
- How can we do this?
- The types document is an example of this cross-collaboration
- OpenSSF could incubate things that feeds into other groups?
- There is guidance from various governments already
- We should look at what these say and identify overlap
- Allan will share links to the various government SBOM guidance
- We should look for commonality and differences in these documents
- Dutch SBOM https://www.ncsc.nl/documenten/publicaties/2023/juli/5/sbom-startersgids
- Germany https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-2.pdf?__blob=publicationFile&v=4
- Japan https://www.meti.go.jp/english/press/2023/0728_001.html
- Mapping all the SBOM fields could also be a valuable task
This SIG has some unique opportunities other SBOM focused groups do not as we are a truly neutral venue. We should take advantage of this status to further some SBOM related efforts that will help the entire industry.
A few examples that came up during the discussion
- There are currently some SBOM guidance documents from the Netherlands, Germany, and Japan that Allan was kind enough to link to. There is going to be differences and overlap in this guidance. We could parse such documents to identify what they have in common and where they differ. This would be a very valuable reference document.
- We could maintain a map of the NTIA minim elements to the actual SPDX and CycloneDX fields. If such a mapping that covers both exists elsewhere we should link to it. If separate mappings exist we can combine those into one reference document.
There are certainly other things we could work on. Please add ideas or comments to this issue to track such efforts. We can split out specific work into issues as needed.
Metadata
Metadata
Assignees
Labels
No labels