4 ms·
"For US companies, Executive Order 14028, “Improving the Nation's Cybersecurity” now makes providing a SBoM a legal obligation for many companies." Yea, this i
by deviantbit 3y ago
"For US companies, Executive Order 14028, “Improving the Nation's Cybersecurity” now makes providing a SBoM a legal obligation for many companies."
Yea, this is not true. There is NO legal obligation. Be careful with what you read on the internet.
Guidance and law are two very different things.
- mardef 3y agoUntil you are providing software to the US government, in which case it is their requirement. Or at least that was my experience while working on sovereign cloud stuff in big tech.
- sheepshear 3y agoThey're notifying companies that do regulated work to check if their compliance obligations have changed. It's not an address to the general public telling us that our gadgets will be different now.
- kube-system 3y agoObligations under regulatory law are correctly called "legal obligations". They might not apply to you, but they may still exist for "many" others.
- deviantbit 3y agoAgain. Not true.
- kube-system 3y agoYes, it is true. https://en.wikipedia.org/wiki/Regulatory_law https://en.wikipedia.org/wiki/Regulatory_law And EO 14028 does it: https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/information-technology-category/it-security/executive-order-14028 https://www.gsa.gov/technology/it-contract-vehicles-and-purc...
- genmud 3y agoIf you sell software to the government you do. Which happens to be the biggest purchaser of software and touches others by proxy. E.G. you might provide software to Boeing who sells to the government, therefore Boeing has a legal obligation and requires all its suppliers to provide SBoMs. Or Dell, or HPE, or Cisco or literally every software / service provider.
- deviantbit 3y agoThis is not true either.
- genmud 3y agoI own a defense company, work on security stuff, I can assure you it is.
- deleted 3y ago[deleted]
- deviantbit 3y agoFunny. So do I. Military specs are governed through something call MIL-STD, not through NIST unless it directly references it. For instance BSSC 2005 gives guidelines on coding standards for Java, but no one follows them. If you were a contractor then you would know all specifications are waived unless specifically designated by your MOL and documented in GSA/SOW. So here is one of these internet know it all's that doesn't know anything.