An organization's security team is enhancing its software supply chain risk management practices for newly acquired third-party applications. To proactively verify that external vendor applications do not introduce known vulnerabilities from embedded open-source libraries, which of the following artifacts should the organization require vendors to provide?
- A Software Bill of Materials (SBOM)Answer
- BA Business Impact Analysis (BIA)
- CAn Interconnection Security Agreement (ISA)
- DA Service Level Agreement (SLA)
Answer
The organization should require vendors to provide a Software Bill of Materials (SBOM).
Requiring a Software Bill of Materials (SBOM) allows organizations to maintain continuous visibility into the component libraries and open-source software embedded within vendor-supplied applications. This inventory is critical for analyzing supply chain risks and reacting promptly when vulnerabilities are discovered in common upstream libraries.
Step-by-Step Solution
Key Concept
Software Bill of Materials (SBOM) in Supply Chain Security
Estimated Time:1m 15s