Supply Chain Forum 2025: Advancing Transparency with the BOM Maturity Model
Skills:
Security Basics70%
๐๏ธ Steve Springett, Vice Chair on the Board of Directors, OWASP Foundation
๐ Presented at Supply Chain Cybersecurity Forum 2025
In an era of increasing software supply chain complexity and regulatory scrutiny, the ability to generate, manage, and assess Software Bill of Materials (SBOMs) is no longer optional, it's essential. This talk delves into the OWASP Software Component Verification Standard (SCVS) and focuses on the recently introduced BOM Maturity Model, a practical framework for evaluating the depth and quality of BOM artifacts.
Attendees will gain an understanding of how the BOM Maturity Model complements SCVS and SBOM formats including CycloneDX and SPDX, offering a structured path from basic inventory tracking to rich, actionable metadata that supports risk analysis, vulnerability management, and compliance. Through real-world scenarios and guidance, this session will help teams assess their current SBOM practices and plan meaningful improvements.
Whether you're just starting your SBOM journey or looking to advance your capabilities, this session provides a roadmap to more trustworthy and transparent software supply chains.
View upcoming Summits: https://www.sans.org/u/DuS
Watch on YouTube โ
(saves to browser)
Sign in to unlock AI tutor explanation ยท โก30
Playlist
Uploads from SANS Institute ยท SANS Institute ยท 0 of 60
โ Previous
Next โ
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS Institute
SANS Institute Cybersecurity Training Customer Stories
SANS Institute
SANS Institute UK Cyber Academy
SANS Institute
SANS Institute UK Cyber Academy
SANS Institute
CISSPยฎ Prep Exam, MGT414, by SANS Institute
SANS Institute
SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute
Information Security Training from SANS Institute - Student Testimonials
SANS Institute
SANS NetWars
SANS Institute
SANS DFIR NetWars
SANS Institute
Hack The Drone - SANS Cyber Academy UK
SANS Institute
SANS VetSuccess Immersion Academy
SANS Institute
SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Institute
The 2015 SANS Holiday Hack Challenge
SANS Institute
SANS VetSuccess Academy: Hands-on Skills
SANS Institute
SANS VetSuccess Academy Overview
SANS Institute
SANS ICS Security Summit & Training 2017
SANS Institute
Exploring the Unknown Industrial Control System Threat Landscape โ SANS ICS Security Summit 2017
SANS Institute
WannaCry recap, patches, and analysis
SANS Institute
If Weโre Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
SANS Institute
Graduation Day - SANS HM Gov Cyber Retraining Academy
SANS Institute
Incentivizing ICS Security: The Case for Cyber Insurance โ SANS ICS Security Summit 2017
SANS Institute
SANS Data Breach Summit & Training 2017
SANS Institute
SANS Secure DevOps Summit & Training 2017
SANS Institute
How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
SANS Institute
SANS Webcast โ Continuous Opportunity: DevOps & Security
SANS Institute
SANS Cybersecurity Programs for the Department of Defense
SANS Institute
SANS Pen Test HackFest Summit & Training 2017
SANS Institute
SANS SIEM & Tactical Analytics Summit & Training
SANS Institute
If Weโre Doing So Well, Why Are We Still Doing So Poorly? โ SANS ICS Security Summit 2017
SANS Institute
SANS Institute
SANS Institute
ICS515: ICS Active Defense and Incident Response
SANS Institute
SANS Institute
SANS Institute
Introducing the NEW SANS Pen Test Poster
SANS Institute
SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute
SANS ICS Security Training, Munich, Germany
SANS Institute
SANS Automotive Summit Webcast
SANS Institute
Privesc Playground - SANS Pen Test HackFest Summit 2017
SANS Institute
Introduction to Reverse Engineering for Penetration Testers โ SANS Pen Test HackFest Summit 2017
SANS Institute
Honey, Please Donโt Burn Down Your Office: Fun with Smart Home Automation
SANS Institute
SANS Security Operations Summit & Training 2018
SANS Institute
Sh*t Happens! (But You Still Need to Drink the Water) โ SANS ICS Summit 2018
SANS Institute
ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape โ SANS ICS Summit 2018
SANS Institute
Youโre Probably Not Red Teaming (And Usually Iโm Not, Either) โ SANS ICS Summit 2018
SANS Institute
A Sneak Peak at the New ICS410
SANS Institute
Jumping Air Gaps โ SANS ICS Summit 2018
SANS Institute
Introduction to Linux
SANS Institute
Introduction to Malware Analysis
SANS Institute
Youโre Probably Not Red Teaming (And Usually Iโm Not, Either) Webcast by Deviant Ollam
SANS Institute
Hacking your SOEL: SOC Automation and Orchestration โ SANS Security Operations Summit 2018
SANS Institute
Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
SANS Institute
Apples and Oranges?: A CompariSIEM โ SANS Security Operations Summit 2018
SANS Institute
SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Institute
SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Institute
The Science of Security: The Psychological Impacts of Security Awareness Programs
SANS Institute
How I Pulled Off an Edgy Security Campaign โ SANS Security Awareness Summit 2018
SANS Institute
Practical Advice for Submitting to Speak at a Cybersecurity Conference
SANS Institute
SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Institute
SANS Webcast - Zero Trust Architecture
SANS Institute
SANS STX Cyber Range
SANS Institute
Part 1 โ SANS Institute and Tenable talk about cloud security
SANS Institute
More on: Security Basics
View skill โRelated AI Lessons
โก
โก
โก
โก
The OpenAI Breach Wasn't About OpenAI โ It Was About the 84 Packages Above Them
Dev.to ยท Dimitris Kyrkos
Years of Apple's Best Security Work, Cracked in Five Days โ Here's What Developers Should Know
Dev.to ยท ArshTechPro
TorCT PHP RAT 2026
Dev.to AI
Building a Post-Quantum E2EE Library: Introducing Paranoia.ts (searching contributors)
Dev.to ยท Matรฉo Callec
๐
Tutor Explanation
DeepCamp AI