CISA’s expanded SBOM guidance increases data collection requirements, but fails to address the core challenge of converting SBOM data into operational risk mitigation.
CISA expands SBOM minimum elements with new data fields such as hash values, licenses, and author signatures to enable organizations better software supply chain transparency.
SBOM is a formalized component inventory with standardized data fields and exchange formats (SPDX, CycloneDX) that enables security leaders to automatically track vulnerable components in the supply chain.