This page provides access to SBOM-related resources, including documents, guidance, frameworks, and other reference materials.
SBOM Document Quality Guide
Resource:
- SBOM Document Quality Guide (In Google Doc, In the public review process now.)
- SBOM Document Quality Guide (In Github)
The ”OpenChain SBOM Document Quality Guide” is a format-independent framework focused on the quality of the information contained within the document, such as its accuracy and integrity. It defines the essential quality requirements for achieving robust security assurance and license compliance, providing actionable steps to ensure the reliability of the content.
Key considerations and differences when adapting the Telco SBOM Guide to develop this guide:
- Compatibility: This guide is designed for broad compatibility beyond the “OpenChain Telco SBOM Guide”. By conforming to this guide, an SBOM document not only meets the requirements of the “OpenChain Telco SBOM Guide” but also aligns with various other industry guidelines and regulatory standards.
- Applicability: This guide serves as a foundational quality standard applicable across all industries. Its language and requirements have been carefully refined to ensure universal relevance, making it a basic framework for any sector implementing SBOM Document.
- Format Independence: This guide is written to be independent of any specific SBOM Data format.
- Quality Definition: A new chapter discusses what constitutes a high-quality SBOM Document, explains its importance, and describes how such documents can be effectively utilized.
- Best practices: Guidance addressing various challenges in creating and managing SBOM Documents have been incorporated.
- Practical Examples: As part of these best practices, practical SBOM Document samples are provided in JSON format along with their corresponding schema.
Automotive SBOM Specification
Resource: Automotive SBOM Spec (In Github)
Automotive SBOM is defined as an SBOM standard that follows the general-purpose SBOM specifications but has reconsidered its content specifically for use in the automotive industry. The objectives of Automotive SBOM are as follows:
- Use as a common standard in the automotive supply chain OEMs, as final distributors, are required to carry out various risk management measures to fulfill their safety responsibilities, but this requires that suppliers provide the necessary information accurately and without omission or excess. The Automotive SBOM defines the format, content, and granularity of the information required by OEMs, and by being used as a common guideline for each supplier to create an SBOM that meets the requirements for good products, it will improve transparency and traceability throughout the supply chain.
- Contributing to improving productivity in the automotive industry The Automotive SBOM specifications were created with the intention of being commonly used by OEMs both in Japan and overseas. Currently, because the SBOM specifications required by each OEM differ, suppliers individually create and provide SBOMs tailored to each OEM’s requirements, which consumes a lot of person-hours. Standardizing the requirements from OEMs to suppliers will reduce the burden on suppliers in complying with SBOMs and contribute to improving productivity throughout the automotive industry.
- Use as a requirement specification for tool vendors The information that will become the content of SBOM is generally collected from the target software using an SCA tool, but the functionality and performance of the SCA tools currently available in the market are not perfect. Furthermore, selecting the most suitable SCA tool for use in the automotive industry from among the multiple tools available requires desk research, benchmarking, and performance evaluation, which is difficult for each development team at each company to carry out. The Automotive SBOM specification can be used as a means of specifically communicating the requirements for functional enhancements needed in the automotive industry to SCA tool vendors, and as a criterion for each development team to select tools.
Telco SBOM Guide
Resource: Telco SBOM Guide
This document “OpenChain Telco SBOM Guide” aims to outline certain requirements related to how an entity creates, delivers, and consumes Software Bill of Materials (SBOM), so that entities that produce and/or consume SBOMs that conform to this guide can ensure repeatability and streamlining of tools and processes for generating and consuming SBOMs. Please Note that this guide does not require a conforming entity to adopt OpenChain (in any version) but doing so is greatly encouraged.
This guide is designed to work on a per SBOM level: an entity can use it as its sole way of delivering SBOMs but it is the individual SBOM that the guide refers to, not the entity that provides the SBOM. An SBOM using this guide can be called “OpenChain Telco SBOM Guide Compatible.”
Releasing SBOMs that match the requirements outlined in this guide does not preclude an entity from also delivering SBOMs for the same software in alternate ways or formats.
