Working with the world's largest enterprises and global policymakers to address the complexities of optimizing your software supply chain with SBOMs, Sonatype announced SBOM Manager.
This solution provides an integrated approach to managing SBOMs from third-party vendors, alongside those SBOMs created for your own software, powered by Sonatype's unique data and security research.
By enabling comprehensive optimization of SBOM management, Sonatype sets a new standard for compliance, scalability, and cybersecurity.
Through its seamless management of SBOM generation, collection, categorization, and ongoing monitoring, Sonatype SBOM Manager empowers organizations to achieve security and efficiency in their software supply chains, marking a significant advancement on the journey toward integrated and secure software distribution and management.
The digital landscape is witnessing a surge in the demand for greater transparency into software development; from regulations such as the EU's NIS2 Directive to the US Executive Order on Improving the Nation's Cybersecurity to industry mandates like the PCI Security Standards for financial institutions, and specific requirements for medical device manufacturers in the FD&C Act.
These growing requirements underscore the critical need for visibility into software supply chains, making SBOMs an indispensable tool for modern enterprises and government agencies.
Enhanced compliance: Stay ahead of global regulations with tools designed to ensure continuous compliance, reducing the risk of penalties and reputational damage.
Advanced security: Proactively identify and mitigate vulnerabilities within the software supply chain, enhancing your security posture and protecting against potential breaches.
Strategic advantage: Leverage Sonatype's superior data and deep expertise in SBOMs and component scanning to gain a competitive edge in software security and compliance.
Optimize efficiency: Sonatype SBOM Manager significantly reduces the manual effort and complexity involved in handling SBOMs by automating SBOM generation, management, and monitoring.
It also helps prioritize what issues need to be addressed first directly in the workflow.
A powerful, yet easy to use System of Record for all SBOMs - Comprehensive SBOM Management: Generate both CycloneDX and SPDX SBOM formats with ease to share with internal and external stakeholders such as auditors, regulators, compliance officers, customers.
Ingest and import SBOMs from third-party software, including VEX documents, and analyze them to pinpoint components, vulnerabilities, and contextual policy violations.
Monitor for policy violations, manage vulnerability disclosures to partners, and report on application risk in a way that makes it easy to understand across business functions, from procurement, to legal, to software engineering.
Store SBOMs from any source to create your own SBOM repository that you can continuously review and manage, ensuring complete visibility and control.
Initially available as a SaaS solution, on-premise and air-gapped versions will be available in the fall of 2024.
This announcement comes on the heels of another feature Sonatype released earlier this year, artificial intelligence and machine learning component detection which extended the ability to create AI bills of materials.
Currently available for preview, the Sonatype SBOM Manager will be generally available in June 2024.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 19 Mar 2024 13:43:05 +0000