DiscoverBelow the Surface (Audio) - The Supply Chain Security PodcastSBOMs, HBOMs, and Supply Chain Visibility - BTS #50
SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

Update: 2025-05-15
Share

Description

Summary

In this episode, Paul Asadoorian and Joshua Marpet delve into the complexities of compliance, inventory management, and the emerging concepts of SBOMs, HBOMs, and FBOMs (no, not that FBOM). They discuss the importance of understanding the components and origins of hardware and software, the challenges of managing technology lifecycles, and the need for clear standards and regulations in the tech industry. The conversation emphasizes the critical role of asset inventories in maintaining security and compliance in an ever-evolving technological landscape. In this conversation, Joshua Marpet and Paul Asadoorian delve into the complexities of hardware security, the cultural shifts needed in security practices, and the importance of transparency in software and firmware management. They discuss the challenges posed by hardware backdoors, the necessity of Software Bill of Materials (SBOMs), and the hidden risks associated with firmware updates. The dialogue emphasizes the need for a cultural change in how organizations approach security and compliance, advocating for continuous management and transparency to inspire confidence in security practices.

Chapters

00:00 Introduction and Technical Challenges
02:02 Exploring Compliance and Frameworks
05:06 Understanding S-bombs, H-bombs, and F-bombs
10:10 The Importance of Inventory and Asset Management
15:01 Navigating Hardware and Software Lifecycle
19:58 Standards and Regulations in Technology
23:56 The Manchurian Microchip and Hardware Backdoors
27:44 Cultural Change in Security Practices
30:47 The Importance of Transparency and SBOMs
36:39 Challenges in Compliance and Risk Management
42:42 The Hidden Risks of Firmware and Hardware Updates

Comments 
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

Paul Asadoorian