Skip to content

Using SBOM Everywhere to amplify guidance through other public workstreams #46

@joshbressers

Description

@joshbressers

During the meeting on 2024-03-12 a topic came up about how we could work together with other groups, especially government groups, to amplify what we are all doing. The notes from the meeting are below


Amplifying SBOM Everywhere Guidance through CISA SBOM Workstreams


This SIG has some unique opportunities other SBOM focused groups do not as we are a truly neutral venue. We should take advantage of this status to further some SBOM related efforts that will help the entire industry.

A few examples that came up during the discussion

  1. There are currently some SBOM guidance documents from the Netherlands, Germany, and Japan that Allan was kind enough to link to. There is going to be differences and overlap in this guidance. We could parse such documents to identify what they have in common and where they differ. This would be a very valuable reference document.
  2. We could maintain a map of the NTIA minim elements to the actual SPDX and CycloneDX fields. If such a mapping that covers both exists elsewhere we should link to it. If separate mappings exist we can combine those into one reference document.

There are certainly other things we could work on. Please add ideas or comments to this issue to track such efforts. We can split out specific work into issues as needed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions