THE US government and 13 allied nations have updated their guidance on the minimum elements of a software bill of materials (SBOM), focusing on enhancing software supply chain security and transparency. This guidance serves as a foundational tool for organizations to inventory their software components, thereby improving risk management regarding vulnerabilities. Updates include new elements such as Component Hash Algorithm and Data Format Version, while two elements were removed.
The revisions maintain core principles from a 2021 document but broaden their applicability and improve data quality. The updated guidance also notes that specific software types may necessitate additional SBOM elements.