@allanfriedman@infosec.exchange
Post #4205741
2026-07-29 17:08 UTC
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for how much of the software an hashtag#SBOM should actually cover.
https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle
Replies (1)
-
@jbm@infosec.exchange 2026-07-30 10:52
@allanfriedman@infosec.exchange I think it's a mistake to add the component license to the minimum requirements. Different concern, use cases and workflow (licenses do not change with every release nor component version), different consumers (cyber vs IP), and none of the job of the CISA nor any other orgs listed as co-authors. At work, I fight every week with people mixing SBOM for cyber and SBOM for license. I don't have time to lose with that, "if you want a license SBOM or license info in the SBOM take care of it, because I won't do it for you". So tired of that.