Richard (Dick) Brooks’ Post

How easy is it for a software consumer to check a software product for vulnerabilities at any moment in time? Answer: it's trivial if a software supplier is providing an online, up to date Vulnerability Advisory Report (VAR) following National Institute of Standards and Technology (NIST) Guidance; a/k/a Vulnerability Disclosure Report (VDR) "Ensure that third-party suppliers continuously enrich SBOM data with a VAR." https://lnkd.in/gPDbwhiX An example NIST VDR (now called VAR in NIST SP 800-161r1-upd1) indicates the presence of exploitable vulnerabilities, or not, in a single Y/N flag is available here using the CISASAGReader app as an example: "UnresolvedVulnerabilities": "N", https://lnkd.in/eP2hm56j Cybersecurity and Infrastructure Security Agency National Institute of Standards and Technology (NIST) Companies can cycle through hundreds of software products checking for known exploited vulnerabilities in minutes when software suppliers provide access to a NIST Vulnerability Advisory Report (VAR) along with an SBOM, following NIST Guidance. A pilot project demonstrating these capabilities has been submitted by Business Cyber Guardian (TM) to EPRI for consideration

Software Security in Supply Chains: Software Bill of Materials (SBOM)

Software Security in Supply Chains: Software Bill of Materials (SBOM)

nist.gov

To view or add a comment, sign in

Explore topics