Survey Surfaces Uneven Adoption of SBOMs to Secure Software
A survey of 100 security professionals indicates that nearly half (48%) of organizations are not meeting Software Bill of Materials (SBOM) requirements as outlined by the U.S. Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and…
A survey of 100 security professionals indicates that nearly half (48%) of organizations are not meeting Software Bill of Materials (SBOM) requirements as outlined by the U.S. Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and the European Union (EU) Cyber Resilience Act.
47% have not started SBOM integration or are still evaluating tools and practices. Over a third struggle with accurately identifying and tracking open-source components. 29% lack tools and processes to analyze SBOMs for vulnerabilities. Only 38% prioritize fixing the most vulnerable application areas. 88% expect AI to enhance software supply chain security visibility significantly. 35% are aware of AI-related data security and privacy risks. 26% acknowledge potential vulnerabilities in AI-generated code.
Lineaje CISO Nick Mistry noted that AI can facilitate the identification of available fixes for vulnerabilities. However, AI also poses risks, such as the potential for creating exploits for known vulnerabilities, which may increase the number of exploitable vulnerabilities.
Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and the European Union (EU) Cyber Resilience Act.
AI can experience hallucinations, referencing non-existent software packages, which cybercriminals may exploit by creating similarly named malicious packages.
32% of respondents believe their organization will eventually produce software with no vulnerabilities, while 68% are uncertain. Mistry emphasized that secure application development depends on effective processes, which are currently flawed. Vulnerability lists are often extensive and inefficiently managed.
70% of respondents admit to lacking alternative remediation plans when fixes are unavailable. Mistry stressed the need for a unified view of vulnerabilities to enhance collaboration between cybersecurity and application development teams.
Based on reporting by devops.com.
