The TELEMETRY publication Software Bill of Materials in Critical Infrastructure was presented at the 2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), held from 4 to 6 December 2023 in Naples, Italy.
The paper examines regulations concerning software used in critical infrastructure and considers whether mandating Software Bills of Materials could offer benefits in this context. The paper was authored by Lars Andreassen Jaatun, Silje Marie Sørlien, Ravishankar Borgaonkar, Steve Taylor and Martin Gilje Jaatun.
Abstract
Critical infrastructure today is comprised of cyber-physical systems, and therefore also vulnerable to cyber threats. Many of these threats come from within, through malicious code in software updates or bugs that can be exploited. Further exacerbating the issue is the fact that most software suppliers in critical infrastructure are developing proprietary systems and giving out minimal information about the composition of their software products. With the US introduction of a Software Bill of Materials (SBOM) requirement in federal information systems, they are better prepared to deal with cyber incidents. This article examines regulations regarding software in critical infrastructure, and whether there is any benefit to mandating SBOMs in critical infrastructure.
You can access the full paper by clicking here.
