CISA and global partners released updated guidelines for Software Bill of Materials (SBOM), introducing 10 new elements and revising existing ones to enhance software risk management. Despite improvements, critics argue it falls short of addressing fundamental issues in risk reduction and exploitability assessment. Notable changes include increased detail on dependency coverage and incorporation of digital signatures.
However, the omission of the Vulnerability Exploitability eXchange (VEX) and questions about the accuracy of SBOMs remain concerns. CISA also issued guidance on open-source software security, advocating for transparency and open-sourcing government-developed software.