Unsolicited Response

SBOMs & CycloneDX with Steve Springett


Listen Later

Steve Springett is the Chair of the OWASP CycloneDX Core Working Group. CycloneDX is one of the two main machine readable formats that SBOMs are being created in, although CycloneDX can capture all sorts of BOMs.

In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX

If you know the basics, skip to 14:24 where we get into the details

  • Statistics on who is generating and using CycloneDX SBOMs, and the impact of governement regulations on the use.
  • Steve's view of the NTIA Minimum Elements for SBOM v. CycloneDX elements.
  • How CycloneDX tries to capture the completeness of and confidence in the SBOM.
  • The naming problem. CPE, CVE, NVD, SWID, PURL and more. Steve describes the problem and what he thinks is the way forward.
  • Vulnerabilities ... and why Steve thinks VEX is a missed opportunity.
  • Outdated component analysis (this could be very useful in a procurement decision)
  • and more

Links

CycloneDX document: Authoritative Guide To SBOM

ICS-Patch (what to patch when in ICS / risk based decision tree)

S4x24 CFP

...more
View all episodesView all episodes
Download on the App Store

Unsolicited ResponseBy Dale Peterson: ICS Security Catalyst and S4 Conference Chair

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

14 ratings


More shows like Unsolicited Response

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,966 Listeners

Risky Business by Patrick Gray

Risky Business

359 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

Hacked by Hacked

Hacked

180 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,014 Listeners

Click Here by Recorded Future News

Click Here

394 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,849 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

167 Listeners

The Industrial Security Podcast by PI Media

The Industrial Security Podcast

20 Listeners

@BEERISAC: OT/ICS Security Podcast Playlist by Anton Shipulin / Listen Notes

@BEERISAC: OT/ICS Security Podcast Playlist

7 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

117 Listeners

(CS)²AI Podcast Show: Control System Cyber Security by Derek Harp

(CS)²AI Podcast Show: Control System Cyber Security

2 Listeners

Ukraine: The Latest by The Telegraph

Ukraine: The Latest

1,753 Listeners

Det Store Bildet by Brandpeople og Bauer Media

Det Store Bildet

10 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners