{"id":336,"date":"2022-05-23T13:13:10","date_gmt":"2022-05-23T17:13:10","guid":{"rendered":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/?p=336"},"modified":"2026-03-26T15:40:09","modified_gmt":"2026-03-26T19:40:09","slug":"software-threat-management-with-sboms-andalm","status":"publish","type":"post","link":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/2022\/05\/23\/software-threat-management-with-sboms-andalm\/","title":{"rendered":"Software threats only come in one size: devastating"},"content":{"rendered":"\n<p>As devices get more connected, the software is increasingly a key part. Understanding the makeup of the software is vital to checking it for vulnerabilities and threats. Unfortunately, when included in a bill of materials, manufacturers list the software as a single item. With growing cybersecurity risks, it&#8217;s more important than ever to include each component of software builds to check against known risk databases.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How a comprehensive software component list protects against software threats<\/h2>\n\n\n\n<p>Beyond the source code managed by the software development team, typical software builds include source code and objects from external libraries, open-source projects and third-party vendors. Much of this is opaque to the software product development team. So, how do software development teams build a component list?<\/p>\n\n\n\n<p>Ready access to the components that make up the software is a key component for protecting an organization from vulnerabilities. By building and maintaining a software bill-of-materials (SBOM) for all software that an organization creates, organizations have ready access to a software component list.\u00a0<\/p>\n\n\n\n<p>With each new threat discovery, a simple lookup against the organizations&#8217; SBOMs can reveal if vulnerabilities raised by these threats exist in the software. Due to the nature of software threats and vulnerabilities, detection speed is critical in preventing potential catastrophe.\u00a0<\/p>\n\n\n\n<p>How can using an SBOM help protect against threats and vulnerabilities?<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Interrogate the SBOM against vulnerability databases to quickly identify threats<\/li><li>Increase software quality assurance by knowing what software the program is built on<\/li><li>Discover meta data regarding source code authors, library artifacts, open-source components, utility components and third-party software built-in<\/li><li>Benefit from a hierarchical structure that shows the relationships between components<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Leverage SBOMs and Application lifecycle management (ALM)<\/h2>\n\n\n\n<p>Leverage ALM to help generate the software bill-of-materials (SBOM) to track and manage threats and vulnerabilities in a software program. Since continuous integration\/continuous deployment (CI\/CD) is an integral part of the application lifecycle management (ALM) process, teams can incorporate the SBOM build. ALM processes offer comprehensive tracking across the lifecycle, including traceable source code artifacts to requirements.&nbsp;<\/p>\n\n\n\n<p>Learn more about what to include in SBOMs and how ALM can help you proactively identify cybersecurity threats in the whitepaper:\u00a0<strong><a href=\"https:\/\/resources.sw.siemens.com\/en-US\/white-paper-software-bill-of-materials-sbom-proactive-cybersecurity\" target=\"_blank\" rel=\"noreferrer noopener\">Software threats only come in one size: devastating<\/a>.<\/strong><\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-fill\"><a class=\"wp-block-button__link has-white-color has-text-color has-background\" href=\"https:\/\/resources.sw.siemens.com\/en-US\/white-paper-software-bill-of-materials-sbom-proactive-cybersecurity\" style=\"border-radius:10px;background:linear-gradient(180deg,rgb(78,188,188) 4%,rgb(6,153,201) 100%)\" target=\"_blank\" rel=\"noreferrer noopener\">Read the white paper<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>As devices get more connected, the software is increasingly a key part. Understanding the makeup of the software is vital&#8230;<\/p>\n","protected":false},"author":79501,"featured_media":337,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spanish_translation":"","french_translation":"","german_translation":"","italian_translation":"","polish_translation":"","japanese_translation":"","chinese_translation":"","footnotes":""},"categories":[1],"tags":[26,40,39,41,38],"industry":[],"product":[],"coauthors":[18],"class_list":["post-336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-alm","tag-bill-of-material","tag-sboms","tag-software-bill-of-material","tag-software-threats"],"featured_image_url":"https:\/\/blogs.sw.siemens.com\/wp-content\/uploads\/sites\/39\/2022\/05\/Siemens-Software-SW-threats-only-come-in-one-size-devastating.png","_links":{"self":[{"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/posts\/336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/users\/79501"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/comments?post=336"}],"version-history":[{"count":1,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/posts\/336\/revisions"}],"predecessor-version":[{"id":338,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/posts\/336\/revisions\/338"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/media\/337"}],"wp:attachment":[{"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/media?parent=336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/categories?post=336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/tags?post=336"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/industry?post=336"},{"taxonomy":"product","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/product?post=336"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/small-medium-business\/wp-json\/wp\/v2\/coauthors?post=336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}