• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Flyy Tech
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
Flyy Tech
No Result
View All Result

Industry Coalition Urges Congress to Hold off on SBOMs Requirements for Defense Contractors

flyytech by flyytech
December 3, 2022
Home Security
Share on FacebookShare on Twitter


A coalition of cybersecurity industry associations have published an open letter urging the US Congress to delay Software Bill of Materials requirements for defense contractors.

The letter relates to section 4543 of the National Defense Authorization Act for Fiscal Year 2023, which requires the US Department of Defense to establish requirements for a software bill of materials (SBOMs) for contractors.

SBOM refers to a list of all the open source and third-party components and the ingredients that make up those components. This is seen as an essential aspect of software and supply chain risk management as it enables security teams to gain more visibility into third-party risks in their software supply chain.

SBOMs have become an increasing focus for the federal government recently, with President Joe Biden’s executive order ‘Improving the Nation’s Cybersecurity’ in May 2021 including new requirements for software vendors to provide this list as part of their federal procurement process. In addition, in November 2022, the Cybersecurity and Infrastructure Security Agency (CISA) included the use of SBOMs as part of its advisory on securing the software supply chain.

However, the open letter has urged Congress’ Armed Services Homeland Committees to delay this legislation, “while allowing the many executive branch activities related to SBOMs to mature the ecosystem.”

It outlined four key factors that support delaying the legislation in this area:

1. The coalition cited the Cyber Safety Review Board (CSRB)’s July 2022 report into the notorious Log4j event, which highlighted the need for greater maturity around the development of SBOMs before they are written into law. For example, it stated that SBOMs are limited by variances in field descriptions and a lack of version information about catalogued components.

2. The letter argued that Congress and government are currently taking an “uncoordinated approach to policymaking on SBOMs,” further complicating this emerging environment.

3. It also pointed out that if the legislation is enacted as planned, it will apply before federal policies on SBOMs come into force, such as Biden’s executive order. “Left unchecked, these varying mandates can be expected to conflict in design and execution,” and therefore the DoD should observe the effect and use of SBOMs mandated by the order.

4. The coalition cautioned against to the “overly simplistic analogies” used to describe SBOMs, which they noted will need to evolve and change through its lifecycle. Therefore, more time is required to establish the complex formats, procedures, uniformity and protections that are needed to make SBOMs manageable at scale.

The coalition emphasized that it understands the importance of SBOMs and is committed to working with Congress to make them work effectively.

The letter stated: “SBOMs are expected to help organizations reduce cyber risk, but they will need processes, tools and standards to translate SBOMs into improved cybersecurity outcomes. Governments, industry and other stakeholders are already working to develop these processes, tools and standards – efforts that are progressing at an impressive pace. The most constructive step Congress can take to help SBOMs deliver their anticipated benefits is to support this ongoing work and ensure that future laws requiring SBOMs are harmonized across the US government.”

The signatories to the letter were the Alliance for Digital Innovation (ADI), The Software Alliance, the Center for Procurement Advocacy (CPA), the Cybersecurity Coalition and the US Chamber of Commerce.

Commenting, Jamie Scott, founding product manager at Endor Labs, agreed with the coalition’s assertion that SBOMs practices require refinement before being rolled out: “The key question agencies must ask is: What is the required data in an SBOM and what constitutes a quality SBOM from a minimal SBOM?

“If organizations define data quality, they can work with a set of recommended tooling that provides the highest quality of data. But until approved and vetted tooling is created, this will be a struggle given the variances across solutions.”

Putting the responsibility on agencies for this guidance will result in friction and snowflake requirements between agencies, which will cause friction across the ecosystem. We need to start first with reasonable requirements for data and reasonable practices.

“The industry hasn’t established a contract or standard practices and processes that can be followed repeatedly, and the guidance provided doesn’t detail these practices and processes.

“If first we want to establish transparency, much of the tooling exists to achieve this goal. But the practices and processes are unclear across the industry today.”

On November 30, research from CyberSheath found that 87% of US defense contractors are failing to meet basic cybersecurity regulation requirements.



Source_link

flyytech

flyytech

Next Post
A fantastic homage to the past

A fantastic homage to the past

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Google Rolls Out New Chrome Browser Update to Patch Yet Another Zero-Day Vulnerability

Google Rolls Out New Chrome Browser Update to Patch Yet Another Zero-Day Vulnerability

December 3, 2022
LulzBot TAZ SideKick 747 Review: Born in the USA

LulzBot TAZ SideKick 747 Review: Born in the USA

October 3, 2022

Trending.

Image Creator now live in select countries for Microsoft Bing and coming soon in Microsoft Edge

Image Creator now live in select countries for Microsoft Bing and coming soon in Microsoft Edge

October 23, 2022
Allen Parr’s false teaching examined. Why you should unfollow him.

Allen Parr’s false teaching examined. Why you should unfollow him.

September 24, 2022
Review: Zoom ZPC-1

Review: Zoom ZPC-1

January 28, 2023
Elden Ring best spells 1.08: Tier lists, sorceries, incantations, and locations

Elden Ring best spells 1.08: Tier lists, sorceries, incantations, and locations

January 14, 2023
CPU Benchmarks Hierarchy 2022: Processor Ranking Charts

CPU Benchmarks Hierarchy 2022: Processor Ranking Charts

September 11, 2022

Flyy Tech

Welcome to Flyy Tech The goal of Flyy Tech is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Follow Us

Categories

  • Apple
  • Applications
  • Audio
  • Camera
  • Computers
  • Cooking
  • Entertainment
  • Fitness
  • Gaming
  • Laptop
  • lifestyle
  • Literature
  • Microsoft
  • Music
  • Podcasts
  • Review
  • Security
  • Smartphone
  • Travel
  • Uncategorized
  • Vlogs

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent News

Here’s how to backup your devices

Here’s how to backup your devices

March 31, 2023
ESET Research Podcast: Hot security topics at RSA or mostly hype?

ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine

March 31, 2023

Copyright © 2022 Flyytech.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs

Copyright © 2022 Flyytech.com | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT