Category: Guide
SW360
Categories:
FOSSLight
Categories:
OSV-SCALIBR
Categories:
0. Understanding OpenChain
Categories:
1. Organization
Categories:
SBOM Overview
An overview of what an SBOM is and why it is needed, covering software supply chain threats and the benefits an SBOM provides.
Categories:
3.1 Policy
Explains how to establish and communicate a written policy that governs AI SBOM compliance.
Categories:
3.10 Governance
Explains how to establish a governance framework spanning the full AI system lifecycle and review it periodically to reflect emerging AI regulation.
Categories:
3.5 License Obligations
Explains the procedure for reviewing the licenses of an AI system’s code, weights, datasets, and model tree to determine obligations, restrictions, and rights.
Categories:
3.7 Access
Explains how to publicly identify a means for third parties to make AI SBOM compliance inquiries and the internal procedure for responding to them.
Categories:
Appendix
Categories:
EU Cyber Resilience Act (CRA)
Summarizes the SBOM requirements and implementation timeline of the EU Cyber Resilience Act, the first major legislation to establish SBOM as a legal obligation.
Categories:
SBOM Levels and Classification
Summarizes SBOM levels based on the depth of information they contain, and classification based on when they are generated.
Categories:
Minimum Elements of an SBOM
Covers the data fields an SBOM must contain, from the NTIA 2021 minimum elements to the CISA 2025 revision draft.
Categories:
Open Source Policy
Categories:
OWASP AIBOM Generator
Explains how to use the OWASP tool that generates a CycloneDX-format AI SBOM from a Hugging Face model and scores its completeness, together with actual execution screens.
Categories:
Program Foundation
The stage of establishing the foundation of an AI SBOM compliance program. Covers policy, competency, awareness, and scope.
Categories:
2. Policy
Categories:
Standards and Formats
Compares SPDX and CycloneDX, the two standard formats for expressing an SBOM in a machine-readable form.
Categories:
3.2 Competence
Explains how to define the roles and responsibilities of an AI SBOM compliance program and identify and assess the competence required for each role.
Categories:
3.6 Transparency Obligations
Explains the procedure for reviewing transparency obligations imposed by regulation and applying risk mitigation measures to issues such as disclosure of training data.
Categories:
3.8 Effectively Resourced
Explains how to assign responsibility, staffing, funding, and legal expertise to an AI SBOM compliance program, and how to remediate non-conformances.
Categories:
AI Extension Process
The stage of building AI-specific license, transparency, and SBOM processes that extend beyond code to cover models, weights, and datasets.
Categories:
cdxgen
Explains how to use the AI BOM mode of OWASP cdxgen, which generates a CycloneDX SBOM from projects and models, together with actual execution output.
Categories:
Identifiers and Licenses
Covers the PURL, CPE, and SWID identifiers used to consistently point to components, and how to notate SPDX license identifiers.
Categories:
India, Korea, and Other Jurisdictions
Summarizes SBOM recommendation guidelines from India’s CERT-In and other jurisdictions, including Korea.
Categories:
Open Source Process
Categories:
3. Process
Categories:
Regulatory Trends
Summarizes the regulatory standing of SBOM across jurisdictions, and the US executive order and federal procurement pathway.
Categories:
3.3 Awareness
Explains how to ensure that program participants are aware of the AI SBOM policy and objectives, their own contribution, and the implications of non-conformance.
Categories:
3.9 AI SBOM
Explains the procedure and formats for generating and managing an AI SBOM, automation tools, and the verification areas that tools alone struggle to fill.
Categories:
Model and Container Scanners (Lab700x, Trivy, Syft)
Introduces the key features and usage of security scanners that analyze AI model binaries, inference servers, and AI packages.
Categories:
Operations
The stage of establishing a channel to respond to external compliance inquiries and assigning responsibility and resources to the program.
Categories:
3.4 Program Scope
Explains how to clearly declare the scope and limits to which the AI SBOM compliance program applies.
Categories:
Adoption Roadmap
Summarizes the activities organizations undertake to build an SBOM program in stages, from establishing the foundation to operational maturity.
Categories:
4. Tools
Categories:
Governance
The stage of establishing a governance framework across the full AI system lifecycle and reflecting emerging AI regulations.
Categories:
A Practical Guide to SBOM (Software Bill of Materials)
A guide covering the Software Bill of Materials (SBOM), from its concepts and standard formats to regulatory trends, adoption roadmap, tools, vulnerability management, and governance, organized from the perspective of practitioners in Korea.
Categories:
AI SBOM Compliance Guide
An enterprise practice guide that explains the requirements of the OpenChain AI SBOM Compliance Guide (Version 1.0) clause by clause.
Categories:
Tools and Automation
Covers SBOM generation, management, and scanning tools, and where automation ends and human responsibility begins.
Categories:
5. Training
Categories:
Tools
Introduces the key features and usage of open source tools that generate and analyze AI SBOMs, with actual execution screens.
Categories:
6. Conformance Declaration
Categories:
Vulnerability Management and VEX
Covers how to link an SBOM to vulnerability data for tracking, and the VEX/CSAF framework for exchanging exploitability information.
Categories:
Sharing and Governance
Summarizes SBOM access control and disclosure scope, secure sharing channels, and roles-and-responsibilities governance.
Categories:
Recommendations and Checklist
Collects the key recommendations from the preceding sections and provides a checklist for reviewing SBOM adoption.