Specifies requirements for a Software Bill of Materials (SBOM) that includes comprehensive software component information and upstream relationship assertions, in alignment with CISA and NTIA guidelines, to support Cybersecurity Supply Chain Risk Management (C-SCRM) activities.
Data delivered using this Data Item Description (DID) specifies the requirements for a Software Bill of Materials (SBOM) that includes comprehensive software component information and upstream relationship assertions in alignment with CISA and NTIA guidelines. The SBOM will ensure suppliers/vendors maintain and/or improve Cybersecurity Supply Chain Risk Management (C-SCRM) activities. This approach provides a consistent and repeatable approach for sharing product component data.
a. SBOM Types. Vendors should specify the type of SBOM provided based on the software development stage. Possible types include Design, Source, Build, Analyzed, Deployed, and Runtime SBOMs.
b. Each software component entry must include information about its upstream relationships.
c. The word "item" is used throughout the document to refer to software components of the system.
d. This DID contains the format, content, and intended use information for the data product resulting from the work task described in the solicitation.
e. This DID should be tailored in the Contract Data Requirements List (CDRL) to include only the required specific data elements from Table 1. Examples of specific uses for the data and the data elements that could be used for each purpose follows:
(1) Software Bill of Materials (SBOM) data can be used to establish the details and supply chain relationships of various components used in building in a system. The SBOM will provide managers essential information that enables the identification, forecasting, mitigation, and management of software security. The data will be used to form a foundational data layer on which further security tools, practices, and assurances can be built.
The Minimum Elements For a Software Bill of Materials (SBOM) https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf
Types of Software Bill of Materials (SBOM) https://www.cisa.gov/resources-tools/resources/types-software-bill-materials-sbom
Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM) https://www.ntia.gov/files/ntia/publications/ntia_sbom_framing_2nd_edition_20211021.pdf
Minimum Requirements for Vulnerability Exploitability eXchange (VEX) https://www.cyclonedx.org/specification/overview/

Figure Table 1. TABLE 1 Data Items

Figure Table 1 (continued). TABLE 1 Data Items (continued)

Figure Figure 2. Conceptual SBOM graph with upstream relationship assertions