PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 8, 20260 citationsOpen Access

SPDX Response to CISA SBOM Minimum Elements Draft

View Full Paper
KSKate StewartRJRose Mary JudgeGOGary O'Neall

Key Points

  • This commentary addresses the 2025 Minimum Elements for a Software Bill of Materials proposed by CISA, focusing on updates and enhancements.
  • Submitted feedback on the proposed CISA SBOM Minimum Elements
  • Discussed updates on data fields and automation support
  • Provided comments on practices and processes
  • Highlighted the need for clarified data fields in the SBOM
  • Emphasized the importance of automation support in SBOM tooling
  • Recommended improvements to enhance SBOM implementation practices

Abstract

Comment on 2025 Minimum Elements for a Software Bill of Materials submitted by the SPDX (System Package Data Exchange) Project. The Cybersecurity and Infrastructure Security Agency (CISA) announces the publication and request for public comment on draft guidance entitled, “2025 Minimum Elements for a Software Bill of Materials (SBOM)” (2025 CISA SBOM Minimum Elements), which updates the elements of an SBOM to reflect improvements in SBOM tooling and increased maturity of SBOM implementation. CISA requests input on the clarifications and enhancements in the proposed voluntary guidance. https://www.federalregister.gov/documents/2025/08/22/2025-16147/request-for-comment-on-2025-minimum-elements-for-a-software-bill-of-materials The SPDX Project has submitted feedback regarding the proposed 2025 CISA SBOM Minimum Elements document. The document includes comments on data fields update, automation support update, practices and processes update, and general comments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Stewart et al. (2025) studied this question.

synapsesocial.com/papers/6988291e0fc35cd7a884936bhttps://doi.org/10.5281/zenodo.18506815
Ask AI
Helpful
Bookmark
Share
View Full Paper