Earlier quoted context omitted.
It sounds like you and your fellow employees are generating those sboms while on the clock. In other words, your employer is paying for those sboms, indirectly, already. From your employer's point of view, sboms are an expense. Maybe it's a small expense, maybe it's a big one. If it gets big enough, I suppose they might consider outsourcing it.
It's an automated process. Takes a day at most to set it up if you don't have it already
Open source projects could sell SBOM fragments
61–64 of 64 posts
Re: Open source projects could sell SBOM fragments
#62Earlier quoted context omitted.
Enterprise also doesn't really care. It is just another box to tick and an excel sheet to fill out, correctness isn't actually required. You just need something to put in the list, so you may as well purchase something wrong but authoritative-looking in bulk.
When some new version of log4j comes about and everyone is scrambling to find out where it resides, the cybersecurity team is going to hate the crappy checkbox solution that doesn't actually work. Which is pretty much the norm.
Nobody cares, it's just another checkbox/policy. Security team is just another compliance department. It does not bring in money.
Re: Open source projects could sell SBOM fragments
#63This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?
The point that's most important is: plausible deniability, because with formal and contractual agreements comes the responsibility shift. Enterprise buys software consultancy services because they are the ones that get the blame if it's not compliant with the legal requirements for it or when an audit fails at a later point.
Re: Open source projects could sell SBOM fragments
#64Earlier quoted context omitted.
When some new version of log4j comes about and everyone is scrambling to find out where it resides, the cybersecurity team is going to hate the crappy checkbox solution that doesn't actually work. Which is pretty much the norm.
40% of all log4j downloads are still vulnerable versions. Nobody cares, it's just another checkbox/policy. Security team is just another compliance department. It does not bring in money.
This. Thanks for highlight it!