Article Details

Scrape Timestamp (UTC): 2023-11-21 13:58:11.840

Source: https://www.theregister.com/2023/11/21/the_great_xbom_vs_sbom/

Original Article Text

Click to Toggle View

The XBOM vs SBOM debate. Why an eXtended Software Bill of Materials could be the next step up in cybersecurity. Webinar A Software Bill of Materials (SBOM) has become a non-negotiable requirement to meet regulatory and buyer requirements. But does this provide enough protection if it can give only a partial view into interconnected and ever-changing application attack surfaces? Introduced in May 2021 when the US Government issued its Executive Order on Improving the Nation's Cybersecurity, SBOM is a tool to manage and secure applications providing a comprehensive list of all software components, dependencies, and metadata associated with an application. While it surveys the foundational building blocks of an application, is this enough? To get a more accurate, comprehensive view of your application, infrastructure, and pipeline components, perhaps you need more – an eXtended software bill of materials which pull SBOMs up to a higher level of veracity, for example. XBOMs can build on top of SBOMS to give you an exhaustive inventory of all your application and supply chain components, associated risks, and how they change over time. You can learn more by joining our latest webinar ­- Why You Need an XBOM: An eXtended Software Bill of Materials - on 28 November at 5pm GMT/12pm ET/8am PT. You'll find out how and why your SBOM might be is lacking and how an XBOM can take your application and supply chain security program to the next level. Sign up to watch the webinar here and we'll send you a reminder when it's time to log in. Sponsored by Apiiro.

Daily Brief Summary

MISCELLANEOUS // Enhancing Cybersecurity with the eXtended Software Bill of Materials

A Software Bill of Materials (SBOM) is now essential to meet regulatory and buyer demands, providing a detailed list of an application's components and metadata.

The U.S. Government's Executive Order from May 2021 stressed the importance of SBOMs in improving the nation's cybersecurity.

Critics suggest that SBOMs may not offer a complete view of application attack surfaces due to their complexity and continuous evolution.

The concept of an eXtended Software Bill of Materials (XBOM) has been introduced as a way to provide a more accurate and comprehensive understanding of applications, infrastructure, and pipelines.

XBOMs aim to enhance SBOMs by offering a fuller inventory of application components, related risks, and tracking modifications over time.

A webinar titled "Why You Need an XBOM: An eXtended Software Bill of Materials" is scheduled to discuss the limitations of SBOMs and the benefits of XBOMs for application and supply chain security.

The webinar, sponsored by Apiiro, will take place on 28 November and aims to guide attendees on elevating their cybersecurity approach using XBOMs.