Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Vulnerability Handling Task Force Meeting Minutes

Tobie,

 

Regarding: “Best current practise for SBOM in open source projects”

The US Government follows NIST Guidance for SBOM implementation best practices for all software products, which you will find here:

https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains-software-1

 

This NIST SBOM guidance information is also referenced in the SPDX SBOM V 2.3 spec under appendix K:

https://spdx.github.io/spdx-spec/v2.3/how-to-use/#k19-linking-to-an-sbom-vulnerability-report-for-a-software-product-per-nist-executive-order-14028

 

There is also an #SBOM SIG on LinkedIn public group (anyone can post/view) where SBOM implementers share insights and best practices on successful SBOM implementation, both SPDX and CycloneDX SBOMs are discussed;

https://www.linkedin.com/groups/13274064/

 

Thanks,

 

Dick Brooks

  

Active Member of the CISA Critical Manufacturing Sector,

Sector Coordinating Council – A Public-Private Partnership

 

Never trust software, always verify and report!

Risk always exists, but trust must be earned and awarded.

https://businesscyberguardian.com/

Email: dick@xxxxxxxxxxxxxxxxxxxxxxxxx

Tel: +1 978-696-1788

 

 

From: open-regulatory-compliance <open-regulatory-compliance-bounces@xxxxxxxxxxx> On Behalf Of Tobie Langel via open-regulatory-compliance
Sent: Thursday, June 19, 2025 1:07 PM
To: Open Regulatory Compliance Working Group <open-regulatory-compliance@xxxxxxxxxxx>
Cc: Tobie Langel <tobie@xxxxxxxxxxxxxx>
Subject: [open-regulatory-compliance] Vulnerability Handling Task Force Meeting Minutes

 

Hi all,

 

 

 

As agreed during today's call, please use this email thread to discuss topics for potential TF deliverables.

 

Here are some possible topics that were raised:

  • A document describing the role and obligations of stewards
  • Best current practise for SBOM in open source projects
  • Describing the relation between open source projects and manufacturers in regards to vuln management

Additionally, it might be worth getting acquainted with the deliverables plan as it contains a number of deliverables that might be interesting for this TF to get involved with or to drive.

 

Best,

 

--tobie

---
Tobie Langel
Tech Lead ORC WG, Eclipse Foundation
Principal, UnlockOpen


Back to the top