DiscoverRelating to DevSecOpsEpisode: #070: Putting da BOM in SBOM and SCA
Episode: #070: Putting da BOM in SBOM and SCA

Episode: #070: Putting da BOM in SBOM and SCA

Update: 2024-05-08
Share

Description

Send us a text

Ken and Mike discuss supply chain security, including software composition analysis (SCA) and software bill of materials (SBOM). They highlight the importance of understanding the components that make up your software and the risks associated with using third-party libraries. They also discuss recent supply chain failures, such as the XZ library hack and the SolarWinds attack. The hosts emphasize the need for organizations to stay up to date with software patches and to consider the security of commercial off-the-shelf software. They caution against placing too much focus on any one security tool or approach, including SBOM, and instead advocate for a well-rounded approach to security.

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Episode: #070: Putting da BOM in SBOM and SCA

Episode: #070: Putting da BOM in SBOM and SCA

Ken Toler and Mike McCabe