OWASP / samm

SAMM stands for Software Assurance Maturity Model.
397 stars 134 forks source link

SBOM and OBOM question #579

Closed stevespringett closed 2 years ago

stevespringett commented 3 years ago

In Implementation \ Secure Build it states:

Create records with Bill of Materials of your applications and opportunistically analyze these.

This should likely be renamed Software Bill of Materials (SBOM). But I cannot find anywhere in Operations to maintain an Operations Bill of Materials. Applications are typically deployed to something. Often times its an application server which is running on an operating system. These additional components form the full stack of an Operations Bill of Materials, but it appears to be assumed and an indirect requirement. I believe this is likely related to #128.

For reference, BSIMM specifically calls out operations bill of materials.