November 2-3 | Renaissance Arlington Capital View, Virginia, USA

Scaling Risk Analysis from Software to Systems (W02a)

How SPDX facilitates compliance, enhances security visibility, and help manage software risks.
12 Nov 2025
13:30

Scaling Risk Analysis from Software to Systems (W02a)

Software Bill of Materials are starting to mature now, and are being incorporated as part of systemic risk analysis. However it’s clear that we need to consider the full system BOM across a product lifecycle to have sufficient information for effective and efficient risk analysis. With the growing prevalence of AI, understanding all the components that make a model, as well as the data sets and process for training that model, are areas that clearly require similar levels of transparency as software. Similarly with the advent of digital twins, firmware, and other software technologies that mimic hardware, being able to be explicit as to what is running on which targets is going to be even more critical. This need has been recognized in community initiatives like AIBOM, HBOM, DBOM, xBOM, etc. however linking this knowledge together in a way that can be reasoned about in a systematic fashion, has been lacking.

With SPDX 3.0, we introduced the Security, AI and Dataset profiles that enabled elements in these domains to be linked via relationships to the software elements. It’s able to link together metadata for design, source, build, deploy, runtime, and analysis SBOMs. As well as handle the needs merging AI transparency requirements from the cybersecurity community and the FDA’s AI guidance. However these extensions fall short of enabling automated monitoring of all the risks that need to be tracked in product lines evolution. With SPDX 3.1, new profiles for hardware (physical and virtual), operations, and safety are being introduced, to enable capturing the appropriate metadata to enable reasoning about systems, at various points in their lifecycle.

In this talk, the SPDX metadata language that will enable databases to be created to monitor product life cycles, cyber security risks and safety hazards is reviewed. At any point in time such databases can export “SBOM documents, “AIBOM documents”, etc. for sharing between organizations and comply with relevant minimum elements as defined by various agencies, as well as supporting a much richer set of metadata that enables proper product line management, and automates conformance with safety profiles after security fixes.