DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
  • United States flag United States
  • Australia flag Australia
  • United Kingdom flag United Kingdom
  • Europe flag Europe
  • New Zealand flag New Zealand
  • Canada flag Canada
DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
DefSec Wire
No Result
View All Result
Home Cyber

CISA and partners unveil updated software bill of materials resource to improve transparency, security and risk-informed decision-making

Thomas Ardern by Thomas Ardern
July 29 2026
in Cyber, Security
0
172
SHARES
2.5k
VIEWS
Share on LinkedInFacebookTwitter

The Cybersecurity and Infrastructure Security Agency, working with other U.S. agencies and international partners, has issued updated guidance defining what a Software Bill of Materials should contain in 2026, widening its scope to cover open-source software, AI software, and software-as-a-service. The revision follows a public comment period that drew more than 90 submissions and is intended to help organizations make more informed risk decisions and automate supply chain management.

You Might Also Like

CISA rolls out new cybersecurity resources for K-12 schools and districts

Global partners meet in Guam for a multilateral SHORAD symposium

“This advancement in SBOM minimum elements reflects the advancements we have made as a community in supply chain security. As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity. “The comments CISA received significantly contributed to this timely revision, and we thank the SBOM community for their engagement.”

The document builds on the National Telecommunications and Information Administration’s 2021 Minimum Elements for SBOM, reflecting lessons from broader deployment of SBOM tools over the past several years. Among the additions are fields for Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Several existing elements were renamed for clarity, including changing Author of SBOM Data to SBOM Author, Supplier Name to Component Producer, and Version of the Component to Component Version. A summary of changes is provided in an appendix.

An SBOM is a formal inventory of the components within a software package and the relationships among them. Advocates say SBOMs help producers, purchasers, and operators understand software supply chains, identify vulnerable dependencies, and respond more quickly to emerging threats—an area of heightened attention since high-profile supply chain compromises and vulnerabilities earlier in the decade.

CISA said the updated minimum elements are designed to be used in machine-readable workflows and to support scalable supply chain security practices across both government and industry. The new guidance is available on CISA’s website.

Tags: Cybersecurity and Infrastructure Security Agency
Previous Post

NSA and CISA co-author updated software bill of materials (SBOM)

Next Post

Navy to decommission the littoral combat ship USS Fort Worth

Thomas Ardern

Thomas Ardern

Thomas Ardern is a journalist reporting on military developments in cyber and advanced defence research. He covers emerging technologies, innovation and the evolving landscape of modern warfare.

Related News

CISA rolls out new cybersecurity resources for K-12 schools and districts

by Thomas Ardern
August 12 2026
0

The Cybersecurity and Infrastructure Security Agency has released the K-12 Cybersecurity Foundations Resource Package, a collection of guides, videos, and...

Global partners meet in Guam for a multilateral SHORAD symposium

Global partners meet in Guam for a multilateral SHORAD symposium

by Stephanie Clarke
August 11 2026
0

Representatives from 11 allied and partner nations joined U.S. military and civilian organizations in Tumon, Guam, for the second annual...

CISA, FBI and partners warn of Gunra ransomware targeting multiple critical infrastructure sectors

by Thomas Ardern
August 10 2026
0

A coalition of U.S. and South Korean law enforcement and cybersecurity agencies issued a joint advisory warning about “Gunra,” a...

NSA joins FBI and others in issuing guidance to defend against Gunra ransomware

NSA joins FBI and others in issuing guidance to defend against Gunra ransomware

by Lila Carvello
August 10 2026
0

The National Security Agency said it has joined the FBI and partner agencies to issue a joint cybersecurity advisory on...

Next Post
DOW awards $55 million grant for Nathan F Twining elementary and middle school at Grand Forks Air Force Base, North Dakota

Navy to decommission the littoral combat ship USS Fort Worth

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending News

Air Force overhauls officer developmental education

Air Force unveils FY26 aviation bonus program

April 8 2026
T-38 Talon operations paused

T-38 Talon operations paused

May 19 2026
Air Force rolls out myBodyComp, reiterates July 31 deadline for waist-to-height ratio checks

Air Force rolls out myBodyComp, reiterates July 31 deadline for waist-to-height ratio checks

July 23 2026

About

DefSec Wire reports on the news that matters in the Defense, Security and Intelligence industries across the United States and the world.

Our Network

  • DefSec Wire
  • DefSec Wire Australia
  • DefSec Wire UK
  • DefSec Wire Europe
  • DefSec Wire New Zealand
  • DefSec Wire Canada

DefSec Wire

  • About Us
  • Advertise
  • Contact
  • Our Team
  • Join Our Team
  • Contribute to DefSec Wire
  • Ethical Tech

Legal

  • Terms of Service
  • Privacy Policy

Categories

  • Air
  • Air Force
  • Army
  • Cyber
  • Defense
  • Foreign Military Sale
  • Industry
  • Land
  • Logistics
  • Marine Corps
  • Military Operations
  • Navy
  • Research & Development
  • Sea
  • Security
  • Space
  • Space Force

Popular Tags

7th Fleet Air National Guard Arleigh Burke-class Boeing Cybersecurity and Infrastructure Security Agency Defense Advanced Research Projects Agency Defense Counterintelligence and Security Agency Defense Logistics Agency Defense Security Cooperation Agency Department of Defense Department of State Department of the Air Force DLA Disposition Services DLA Energy DLA Weapons Support F-35 Foreign Military Sale HII Indo-Pacific Ken Wilsbach L3Harris Lockheed Martin Mark Simerly National Security Agency NATO Pete Hegseth Raytheon RTX Somalia Troy Meink U.S. Africa Command U.S. Air Force U.S. Army U.S. Central Command U.S. Marine Corps U.S. Military Operation U.S. Navy U.S. Southern Command U.S. Space Command U.S. Space Force USAFRICOM USCENTCOM USINDOPACOM USSOUTHCOM USSTRATCOM

Recent Posts

  • ACC’s Point Defense Task Force reshapes installation defense against aerial threats
  • 374th Logistics Readiness Squadron pivots from tasking to airlift in Kumamoto earthquake response
  • Joint statement from second Angolan–American defense cooperation committee meeting
  • Tenacious Archer 2026 boosts joint air defense readiness in Palau
  • L3Harris opens Rhode Island facility to bolster US and allied naval readiness
  • U.S. Space Command hosts JSOU enlisted academy gateway course for the first time
  • Hegseth renames Joint Base Charleston in honor of Sen. Lindsey Graham
  • CISA rolls out new cybersecurity resources for K-12 schools and districts

© 2026 DefSec Wire – part of the DefSec Wire Group.

No Result
View All Result
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security

© 2026 DefSec Wire – part of the DefSec Wire Group.