SBOM 在整个供应链中的作用和好处 (2019)

ID:64193

大小:0.89 MB

页数:28页

时间:2023-06-29

金币:10

上传者:亚森
Roles and Benefits for SBOM Across the Supply Chain
NTIA Multistakeholder Process on Software Component Transparency
Use Cases and State of Practice Working Group
Introduction 2
The Software Supply Chain 4
About this document: Goals and Methodology 4
Perspective: Produce Software 5
Reduce unplanned, unscheduled work 6
Reduce code bloat 7
Adequately understand dependencies within broader complex projects 7
Know and comply with the license obligations 7
Monitor components for vulnerabilities 7
End-of-life (EOL) 8
Make code easier to review 8
A blacklist of banned components 8
Provide an SBOM to a customer 8
Perspective: Choose Software 9
Identify potentially vulnerable components 9
A more targeted security analysis 10
Verify the sourcing 10
Compliance with policies 10
Aware of end-of-life components 10
Verify some claims 10
Understand the software’s integration 10
Pre-purchase and pre-installation planning 11
Market signal 11
Perspective: Operate Software 12
Organization can quickly evaluate whether it is using the component 12
Drive independent mitigations 13
Make more informed risk-based decisions 13
Alerts about potential end-of-life 13
Better support compliance and reporting requirements 13
Reduce costs through a more streamlined and efficient administration 13
Ecosystem, Network Effects, and Public Health Benefits of SBOM 14
Accelerated Vulnerability Management 15
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭