_scurity

CISA SBOM-a-rama 2023

Sharing some highlights and notes from CISA’s SBOM-a-rama I virtually attended. Talks categorized into 3 - Governments & Industry, CISA Working Groups, and Discussion

Overview

Highlights

Governments & Industry

EU Cyber Resilience Act

https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act

Citi

Two main issues identified so far…

New York-Presbyterian Hospital

Takeaways

SBOMs in the Automotive Industry - Auto-ISAC SBOM

3 Phase Approach

Phase 1

Phase 2

Phase 3

Japanese METI Ministry of Economy, Trade and Industry (paused recording)

Trialling rollout across difference sectors - automotive, software and medical

CISA Working Groups

VEX Working Group

Led by: Art Manion

Visualizing a VEX document

VEX implementations

SBOM Sharing

SBOM for the Cloud

SBOM Quality Team

Looking at the table below

On Ramps & Adoption

The end of CVSS - other standards are emerging as better measures of security

Discussion

There was a discussion portion that lasted just over an hour here are the highlights (of what I caught)