|
| 1 | ++++ |
| 2 | +author = "Jason Smith" |
| 3 | +title = "๐ช๐ต๐ผ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐ฏ๐๐ถ๐น๐ฑ๐ ๐ฆ๐๐ข๐ ๐? ๐๐ป๐ฑ ๐๐ต๐ผ ๐ป๐ฒ๐ฒ๐ฑ๐ ๐๐ต๐ฒ๐บ? ๐ค๐" |
| 4 | +date = "2025-05-18" |
| 5 | +linkedin = "https://www.linkedin.com/posts/j28smith_sbom-supplychainsecurity-cybersecurity-activity-7323408174688980993-TPze" |
| 6 | +image = "img/thirdparty/sbom-creators-and-consumers.png" |
| 7 | ++++ |
| 8 | + |
| 9 | +SBOMs are a critical tool for understanding your software supply chain. But not everyone touches an SBOM the same way. |
| 10 | + |
| 11 | +There are ๐ฐ๐ฟ๐ฒ๐ฎ๐๐ผ๐ฟ๐ and there are ๐ฐ๐ผ๐ป๐๐๐บ๐ฒ๐ฟ๐. Sometimes they're the same person, but often they're not. |
| 12 | + |
| 13 | +๐ฉ๐ปโ๐ป ๐๐ฟ๐ฒ๐ฎ๐๐ผ๐ฟ๐ |
| 14 | +These folks generate SBOMs as part of the software build or packaging process: |
| 15 | + ๐ป Development teams |
| 16 | + โ๏ธ CI/CD pipelines |
| 17 | + ๐ฆ Software vendors |
| 18 | + ๐ ๏ธ Tooling platforms |
| 19 | + |
| 20 | +๐ฏ Their job: Ensure SBOMs are accurate, complete and reflect the actual software build artifacts. |
| 21 | + |
| 22 | +๐๐ปโโ๏ธ ๐๐ผ๐ป๐๐๐บ๐ฒ๐ฟ๐ |
| 23 | +These folks use SBOMs to evaluate, verify, or monitor software: |
| 24 | + ๐ก๏ธ Security analysts |
| 25 | + ๐ฆ Software integrators |
| 26 | + โ๏ธ Compliance teams |
| 27 | + ๐ต๐ปโโ๏ธ QA / SRE engineers |
| 28 | + ๐ Customers (especially enterprise/government) |
| 29 | + |
| 30 | +๐ฏ Their job: Use SBOMs to assess risk, validate trust, and meet policy and/or regulatory requirements. |
| 31 | + |
| 32 | +๐ค ๐๐ฒ๐ฟ๐ฒโ๐ ๐๐ต๐ฒ๐ฟ๐ฒ ๐ถ๐ ๐ด๐ฒ๐๐ ๐ถ๐ป๐๐ฒ๐ฟ๐ฒ๐๐๐ถ๐ป๐ด... |
| 33 | + |
| 34 | +If you're a ๐ฐ๐ฟ๐ฒ๐ฎ๐๐ผ๐ฟ, you're responsible for ๐๐ฟ๐๐๐ต. |
| 35 | +If you're a ๐ฐ๐ผ๐ป๐๐๐บ๐ฒ๐ฟ, you're responsible for ๐๐ฟ๐๐๐. |
| 36 | + |
| 37 | +This is why signing SBOMs and supporting cryptographic digital verification is critical. Without that, you might be consuming... misinformation? ๐คทโโ๏ธ |
| 38 | + |
| 39 | +SBOMs aren't just build-time artifacts. They are communication tools across the software lifecycle. ๐ป๐ |
| 40 | + |
| 41 | +Are you generating SBOMs today? Or consuming them from vendors? Do you know if they are trustworthy? ๐ค |
| 42 | + |
| 43 | +#SBOM #SupplyChainSecurity #CyberSecurity #SecureSoftware #OpenSourceSecurity #DevSecOps #DigitalTrust #SoftwareIntegrity #Compliance #SoftwareSupplyChain #BuildSecurityIn |
0 commit comments