A multinational corporation is implementing a new software supply chain risk management strategy. Which of the following approaches would BEST help the security team verify the components and dependencies in third-party software to identify potential vulnerabilities?
The correct answer is Software Bill of Materials (SBOM). An SBOM is a formal, machine-readable inventory of software components and dependencies used in building software. It serves as a key tool in software supply chain security by providing transparency into what components are in the software you're consuming or producing. With an SBOM, organizations can quickly identify if they're using components with known vulnerabilities, track license compliance, and make more informed risk decisions about the software they're using.
Third-party assessment is important but focuses more broadly on evaluating suppliers rather than specifically identifying components within software. Service Level Requirements primarily address performance expectations rather than security component identification. Silicon root of trust is a hardware-based security approach for establishing trusted execution environments and doesn't directly address software component identification.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
Why is identifying vulnerabilities in third-party software important?
Open an interactive chat with Bash
What role does transparency play in software supply chain security?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access