Skip to main content

SBOM business case

SBOM can practically deliver on the following business cases

Risk typeUse case
Software vulnerability riskDoes my system have any critical vulnerabilities?A new critical CVE is announced in component X - which of my systems are impacted?
Export riskDoes my inventory contain any Foreign Ownership, Control, or Influence (FOCI) issues?
Licensing riskDoes my inventory contain any licensing risks - e.g. GPL pollution ?
Support riskUnder CSA (or other) regulations, what software support liabilities exist through dependencies on external (open source?) systems
note

Can we think of any more