What is an SBOM?
A software bill of materials (SBOM) is a list of components that make up your software applications. It includes all the components, libraries, and modules used within a software product, presented in a format that other software can read. Think of this as a list of ingredients that make up your software recipe.
Why do organizations need an SBOM?
Most modern software is built by assembling multiple pre-made, third-party components (like code libraries). When you weave a large number of components together, things can get complicated.
Creating and maintaining an SBOM helps keep track of the versions, licenses, dependencies, and changes made to those components over time. An SBOM is a living document that acts as a source of truth, helping to identify and avoid security risks and satisfy compliance demands.
By providing transparency into a product’s digital makeup, an SBOM is useful to people across every stage of the software lifecycle. This includes people who:
- Develop or manufacture software: Builders can make sure components are up to date and fit their needs.
- Select or purchase software: Buyers can evaluate risk before buying by analyzing the internal makeup of the software.
- Operate software: System administrators and IT teams can check their software against common vulnerabilities and exposures (CVE) lists.
- Use software: End users and consumers indirectly benefit from higher baseline security measures.