trade-press
NIST Builds SBOM Use Cases for DevSecOps Pipelines
The NCCoE's example builds move beyond generating an SBOM to integrating cryptographic signing at each build stage and operationalizing vulnerability detection, bridging the June cyber EO's SSDF tasking to actual infrastructure.
NIST's National Cybersecurity Center of Excellence is publishing example builds that show how to use SBOMs for active supply-chain scanning and vulnerability management, rather than simply generating and storing them. The builds integrate cryptographic hashing and signing at each stage of the DevSecOps pipeline. The work responds to the Trump administration's June 6 cyber executive order directing NCCoE to demonstrate SSDF implementation practices. Michael Ogata, NCCoE computer scientist, described the efforts at the Billington Cybersecurity Summit, noting that two example builds have been published so far under the DevSecOps project, with more planned for vulnerability management workflows.