Security & governance · Glossary term
What is Software Bill of Materials (SBOM)?
A structured inventory of software components and relationships associated with a product or artifact, often including versions, suppliers, licenses, and identifiers.
Also called SBOM.
Why does Software Bill of Materials (SBOM) matter?
You need a component inventory to assess affected dependencies, license obligations, and supply-chain exposure when software changes or vulnerabilities emerge.
Software Bill of Materials (SBOM) in practice
Generate the SBOM during the trusted build, bind it to the release artifact, verify it in policy checks, and update it whenever dependencies or packaging change.
What is the common confusion about Software Bill of Materials (SBOM)?
An SBOM is an inventory, not proof that components are secure, correctly licensed, or actually present unless generation and provenance are trustworthy.
Learn Software Bill of Materials (SBOM) in the course
No lesson links to this term yet. Search the course catalog for it.
Related terms
- Provenance AttestationAuthenticated, machine-readable metadata that binds an artifact to claims about how, where, when, and from which inputs it was produced.
- Reproducible BuildA build whose declared source, environment, and instructions can be independently rerun to produce bit-for-bit identical specified…
- Data ProvenanceTraceable information about where data originated, who or what transformed it, which versions were used, and how derived artifacts relate…
- Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.