The rise in cyberattacks and the critical role that software plays in our lives has brought to light the need for increased transparency and accountability in the software supply chain. In May 2021, https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity on improving the nation’s cybersecurity emphasized the importance of SBOMs in protecting the software supply chain.

An SPDX package information section contains information about a software package being described in an SPDX document.

The best way to become familiar with creating an NTIA minimum Elements SPDX SBOM is by manually creating it as a text file.

Another way to create an NTIA minimum elements SPDX SBOM is through a tool such as https://democert.org/sbom/.

Related Articles