Skip to content

Add requirements on encryption of SBOM while stored and transmitted. #155

@Jimmy-ahlberg

Description

@Jimmy-ahlberg

Suggested new material

It would be of interest to add instructions for encryption and access control of SBOMs for use cases where such are required. I don't think it should be mandated but added as an option. SBOM's could very well be sensitive information, thus it is good if our guide adds clarity for when it is needed.

Proposal would be along the lines of: SBOM Access control

SBOM at rest is stored in a access controlled fashion with only authorized individuals able to access the SBOM for approved purposes.

SBOM encryption:

When an SBOM is transmitted or stored, it should be encrypted (according to some specification we can discuss).

Additional comments

This would harmonize with requirements from O-RAN on how to mange SBOMs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions