Glossary
SBOM (Software Bill of Materials)
An SBOM (Software Bill of Materials) is the structured inventory of the components that make up a piece of software — libraries, transitive dependencies, versions and licences — allowing an organisation to determine whether a product is affected by a published vulnerability.
What it is actually for
When a critical vulnerability is published on a widely used library, the operational question is immediate: "are we exposed, and through which product?". Without an SBOM the answer goes through a questionnaire sent to every publisher and comes back in days or weeks. With an up-to-date SBOM it is a lookup in the inventory.
Two formats are the reference: SPDX (ISO/IEC 5962) and CycloneDX (OWASP).
Known limits
An SBOM describes one version of a product: it expires at every update and is only worth having if reissued. It says nothing about whether a vulnerability is actually exploitable in the product's context, nor about the publisher's operational security. It therefore complements the security questionnaire rather than replacing it, and feeds the software side of fourth-party risk. See supply chain cybersecurity.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours