No SBOM, No Trust

Discover why the Software Bill of Materials (SBOM) is rapidly becoming a strategic necessity for Managed Service Providers (MSPs) and enterprise IT leaders. In this episode, Luigi Ferri explains how software supply chain attacks such as Log4Shell and SolarWinds transformed SBOMs from technical documentation into essential tools for IT governance, cyber resilience, software supply chain security, and operational trust. Learn the four stages of SBOM maturity and how MSPs can strengthen transparency, improve vulnerability management, and build competitive advantage through continuous software dependency visibility.


In this episode, we answer to:

Why are Software Bill of Materials (SBOMs) becoming essential for Managed Service Providers (MSPs)?

How can MSPs improve software supply chain security and gain complete visibility over software dependencies?

What are the four stages of SBOM maturity that help organizations strengthen governance, resilience, and operational trust?


Resources Mentioned in this Episode:

US NTIA - National Telecommunications and Information Administration website, article "Software Bill of Materials", link https://www.ntia.gov/page/software-bill-materials


US NTIA - National Telecommunications and Information Administration website, white paper "Software Consumers Playbook: SBOM Acquisition, Management, and Use", link https://www.ntia.gov/sites/default/files/publications/software_consumers_sbom_acquisition_management_and_use_-_final_0.pdf


US NIST website, Executive Order 14028 "Improving the Nation's Cybersecurity: NIST’s Responsibilities Under the May 2021 Executive Order", link https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity


US NTIA - National Telecommunications and Information Administration website, link


Carnegy Mellon University - Software Engineering Institute, article "The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain", link https://www.sei.cmu.edu/blog/the-sei-sbom-framework-informing-third-party-software-management-in-your-supply-chain/


Connect with me on:

LinkedIn: https://www.linkedin.com/in/theitsmpractice/

Website: http://www.theitsmpractice.com

And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.


Credits:

Sound engineering by Alan Southgate - http://alsouthgate.co.uk/


Graphics by Yulia Kolodyazhnaya

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(159)

MSPs: Your AI Contracts Are Obsolete

MSPs: Your AI Contracts Are Obsolete

AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are n...

11 Aug 16min

DARE25: Why Defense Isn't Enough

DARE25: Why Defense Isn't Enough

Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and ad...

4 Aug 9min

ISO 28000: Your Resilience, Their Budget

ISO 28000: Your Resilience, Their Budget

In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using...

28 Jul 13min

PSD3: Who Owns Trust?

PSD3: Who Owns Trust?

PSD3 is more than a compliance requirement, it's a test of organisational maturity, security leadership, accountability, and decision-making. Discover how Enterprise Service Management, IT Service Man...

14 Jul 6min

The Hidden Cost of Untrusted Data

The Hidden Cost of Untrusted Data

Why do organizations struggle to trust their operational data despite having plenty of it? In this episode of The ITSM Practice Podcast, Luigi Ferri explains the critical difference between data quali...

7 Jul 11min

ITIL 5 Foundation: Exam Success

ITIL 5 Foundation: Exam Success

Preparing for the ITIL 5 Foundation exam? Discover why successful candidates focus on understanding the ITIL Value System, Value Chain, Governance, AI Capability, Four Dimensions, and Service Lifecycl...

30 Jun 10min

PSD3: Governance Before Technology

PSD3: Governance Before Technology

In this episode, Luigi Ferri explores why organisations often take the wrong first step when preparing for PSD3 compliance. Rather than rushing into new tools, fraud platforms, or transformation progr...

23 Jun 7min

Populært innen Teknologi

lydartikler-fra-aftenposten
tomprat-med-gunnar-tjomlid
teknisk-sett
elektropodden
rss-ai-forklart
shifter
fornybaren
rss-alt-som-gar-pa-strom
hans-petter-og-co
rss-bak-skyen
rss-ki-praten
rss-digitaliseringspadden
energi-og-klima
smart-forklart
kortslutning
sosialt-sett-om-teknologi-kommunikasjon-og-livet-i-mellom
rss-bouvet-bobler
rss-ki-til-kaffen
rss-teknologioptimistene-energibransjens-it-podcast
rss-grenser-for-ki