The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has released guidance on the Minimum Elements for a Software Bill of Materials (SBOM).
The guidance was authored in collaboration with a range of international partners, including the USA's NSA and FBI, New Zealand’s National Cyber Security Centre and the Canadian Centre for Cyber Security.
An SBOM is described by ASD a nested inventory, a list of ingredients that make up software applications and systems.
Organisations that produce, procure, and operate software can use SBOM data to better understand their software supply chain, while increased software supply chain visibility can drive risk management decisions, including addressing known and newly discovered vulnerabilities and risks, according to the ASD.
The minimum elements set baseline expectations for the data that makes up the SBOM document and how the data is documented and engaged with. They do not create new requirements, but instead refine how organisations should generate and request SBOMs.
Key actions to take for organisations, in relation to the updated guidance, include requesting SBOMs that satisfy the updated SBOM Minimum Elements; using available tools to generate, ingest, and analyse SBOM data; and generating SBOMs that satisfy the updated SBOM Minimum Elements.
Last year, the ASD’s ACSC released guidance to inform organisations about the advantages of integrating an SBOM.




