ossf / sbom-everywhere

Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
Apache License 2.0
70 stars 25 forks source link

Document SBOM use cases #3

Open joshbressers opened 2 years ago

joshbressers commented 2 years ago

TODO: What are the use cases? Document needs to fleshed out and structured. SBOM Use Cases for Security

Kathy Goeschel will take point Bunny Hernandez Cameron Banowsky David Wheeler willing to take a pass at adding in his thoughts. Ran Dall

joshbressers commented 2 years ago

We need to better define the scope and definitions for these use cases

mrutkows commented 2 years ago

This list of SBOM use cases relative to the data needed under CDX was invaluable to me in assessing completeness of SBOMs during SDLC... https://cyclonedx.org/use-cases/

hepwori commented 2 years ago

This from NTIA is a good SBOM use cases reference which I've found useful: https://www.ntia.gov/files/ntia/publications/ntia_sbom_use_cases_roles_benefits-nov2019.pdf

anthonyharrison commented 2 years ago

I wrote a blog post which identified 4 use cases for SBOMs all related to managing risk: