GlossaryAttack surface and pentesting

SBOM

Short answer

An SBOM (Software Bill of Materials) is a machine readable inventory of all the components, libraries and dependencies that make up a piece of software, with their versions and suppliers. It lets organisations know quickly whether they are affected when a vulnerability is found in a component.

Why it matters

Modern software is mostly assembled from open source and third party components. When a serious flaw appears in a widely used library, as happened with Log4Shell in December 2021, the first question is which products contain it. Without an SBOM, answering takes days or weeks; with one, it is a search.

What it contains

For each component: its name, version, supplier, unique identifiers, licence and relationship to other components. The two main standard formats are SPDX and CycloneDX. SBOMs are usually generated automatically during the build process and updated with each release.

Regulation

The EU Cyber Resilience Act requires manufacturers of products with digital elements to draw up an SBOM as part of their technical documentation. In the US, a 2021 executive order made SBOMs a reference practice for software sold to federal agencies. CISA publishes guidance on minimum elements and use.

How it is used

SBOMs feed software composition analysis tools, which match components against known CVEs and help prioritise vulnerabilities. For buyers, asking suppliers for an SBOM is becoming part of third party risk management.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub