Policy · 3h ago
CISA Updates SBOM Guidance, But Risk Gaps Remain
CISA issued fresh SBOM guidance with a couple-dozen field changes to make software bills of materials more comprehensive. Critics argue the framework still lacks real risk-management improvements. The update aims to enhance transparency but may not address deeper security needs.
Meridian48 take
The guidance improves data completeness but sidesteps the harder problem of how SBOMs drive actual risk decisions.
sbomcybersecurity