A Practical Guide for Unlocking Business Value from Your SBOMs (W00c)
Software Bill of Materials (SBOM) generation is just the beginning. This talk explores the downstream lifecycle and practical applications of SBOMs across software production, distribution, and consumption phases. Through a comprehensive use case discussions, the speakers demonstrate how different stakeholders leverage SBOM data to drive business decisions and manage risks. This talk showcases real-world implementations where organizations utilize SBOMs to evaluate security vulnerabilities, ensure compliance, assess licensing implications, and analyze component supportability. The speaker will examine how SBOMs facilitate rapid incident response, inform procurement decisions, and provide visibility into component usage patterns across enterprises. The discussion details the specific NTIA minimum elements and complementary data sources required to achieve these objectives. This framework, along with its accompanying use cases, represents the collaborative effort of an international SBOM Operations working group, bringing together expertise from industry, government, and academic sectors.
BOMOPs tiger team published the white paper with OpenSSF on the topic: Improving Risk Management Decisions with SBOM Data. The White paper was drafter in an open process by a community of Software Bill of Materials (SBOM) experts, facilitated by the Cybersecurity and Infrastructure Security Agency (CISA)
