Cyber

Software bill of materials

Machine-readable inventory of the software components entering a product, of their versions and of their known vulnerabilities, required by the European cyber resilience regulation.

Definition

The software bill of materials is the first instrument allowing the state of an information estate to be measured objectively. An underwriting questionnaire has until now asked whether the business holds a patching policy, a question whose answer is always yes and whose discriminating value is therefore nil. The bill of materials allows one to ask what the estate actually contains, a question whose answer is verifiable by exhibit. Its reach exceeds individual selection: once generalised, it finally makes accumulation measurable, an insurer being able in principle to establish how many of its insureds depend on the same library and to estimate the burden of a critical vulnerability before it occurs. That is exactly the information missing during the major episodes of widely distributed vulnerability, where the market discovered its exposure after the fact.

Example

Two businesses giving identical answers to the same cyber questionnaire may carry incomparable security debts; only the bill of materials tells them apart.

Related terms
Also known as

SBOM, software bill of materials, inventaire de composants logiciels