Post #1257469
2026-03-02 16:37 UTC
I recently presented Deutsche Bahn's ongoing efforts to make its software supply chains more transparent. For the first time, we publicly shared how we set up the internal program, the principles we follow, the overarching architectural blueprint, and the tools we use to create, store, and analyze 80,000+ SBOMs. All of this is to find out, in real time, which of the over 100,000 software components we are using are where and how. [🧵 1/3]
#DeutscheBahn #SBOM #SupplyChain #CRA #NIS2
Replies (1)
-
@mxmehl@mastodon.social 2026-03-02 16:38
Actually, there were two presentations at #FOSDEM. In the first, I focused on the strategic aspects and context of the Cyber Resilience Act (#CRA). Why does DB need transparency of its software supply chains? Why is it damn hard to achieve this? How did we come from idea to strategy to implementation? And why do we need less a technological and rather an organizational and cultural shift to succeed? Answers to these questions in the recording and slides. https://mehl.mx/blog/2026/software-supply-chain-strategy-at-deutsche-bahn/ [🧵 2/3]