{"id":4590,"date":"2022-05-18T11:26:56","date_gmt":"2022-05-18T11:26:56","guid":{"rendered":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?p=4590"},"modified":"2023-08-01T18:08:52","modified_gmt":"2023-08-01T18:08:52","slug":"how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/","title":{"rendered":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4591\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg\" alt=\"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg 800w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-300x150.jpg 300w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-768x384.jpg 768w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-540x270.jpg 540w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-162x81.jpg 162w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-360x180.jpg 360w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security-400x200.jpg 400w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><em><strong>As part of Solutions Review\u2019s\u00a0<a href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noopener\">Contributed Content Series<\/a>\u2014a collection of articles written by industry thought leaders in maturing software categories\u2014Mike Dager, the Chief Executive Officer of <a href=\"https:\/\/www.grammatech.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\" data-linkindex=\"0\">GrammaTech<\/a>, shares some insights on the enterprise security benefits that software bill of materials (SBOMs) can offer to supply chain professionals.<\/strong><\/em><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Supply chain professionals should be familiar with a bill of materials (BOM), which is used to build quality products and support the procurement, inventory management, and resolution of problems involved in creating those products.<\/span><span data-contrast=\"auto\"> A BOM is also used to manage parts and maintenance supplies when buying products. However, software procurement is often more concerned with licensing terms, security requirements, pricing, maintenance, and support needs. While the BOM concept for software procurement is relatively new, it is now becoming an essential piece of managing the software supply chain.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">A Software BOM (SBOM for short), like a traditional BOM, is a list of third-party and open-source components that make up a software product. The SBOM is also responsible for listing the features that various subcomponents rely on and identifying licensing info, software versions, and vulnerabilities.<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">In the past, software was assumed only to contain code and intellectual property developed by the product vendor. However, modern software is no longer developed entirely from scratch and almost always contains third-party and open-source software components. These components may include potential security vulnerabilities the buyer could be introducing into their environment.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">To put the problem in context, a study by <\/span><a href=\"https:\/\/codesentry.grammatech.com\/wp-form-osterman-research\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Osterman Research<\/span><\/a><span data-contrast=\"auto\"> found that 100-percent of widely used commercial software contained vulnerable open-source components. A worrying 85-percent of those analyzed applications had critical vulnerabilities which pose a significant security risk. <\/span><span data-contrast=\"auto\">The most vulnerable applications are daily email and online meeting applications, which is a problem because enterprise organizations widely use these applications and these vulnerabilities present a severe cybersecurity risk.<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">With many high-profile security breaches and attacks linked to purchased software, there&#8217;s now a heightened awareness of software supply chain security and the demand for SBOMs. The recent <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Presidential Cybersecurity Executive Order<\/span><\/a><span data-contrast=\"auto\"> specifically identified the importance of improving the software supply chain. It spotlighted the critical need for SBOMs as a mandated prerequisite for software vendors doing business with the federal government. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">While RFPs, RFIs, and vendor questionnaires are part of the procurement due diligence process, the vendor fills these documents, and the procurement team has to trust them. Meanwhile, an SBOM is a document of \u201ctruth\u201d of what is actually in the software. Generally speaking, procurement departments are not expected to have technical knowledge of the software they purchase. However, it does help to understand what an SBOM should include so you can evaluate supplier SBOMs. At the very least, the components listed in an SBOM need to be well identified to have:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><b><span data-contrast=\"none\">Author Name<\/span><\/b><span data-contrast=\"none\">: The author of the SBOM, usually the organization supplying the software.\u00a0<\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Supplier Name<\/span><\/b><span data-contrast=\"none\">: The name of the software supplier and should include aliases. The supplier and the author might be different if the supplier makes a claim on the author&#8217;s behalf. <\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Component Name<\/span><\/b><span data-contrast=\"none\">: The name of the software component and possible aliases.\u00a0<\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Version String:<\/span><\/b><span data-contrast=\"none\"> The format of the version information is free form but should follow common industry usage.\u00a0<\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Unique Identifier<\/span><\/b><span data-contrast=\"none\">: A unique identifier is needed for each component.\u00a0<\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Relationship<\/span><\/b><span data-contrast=\"none\">: The relationship field defines the relationship between the component and the software package. In most cases, this relation is \u201cincludes,\u201d as in software package X includes component Y. <\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">It\u2019s important to note that basic SBOM information doesn\u2019t necessarily include any security information. To get the most out of SBOMs, they must contain vulnerability details such as:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li data-leveltext=\"\u25cf\" data-font=\"Noto Sans Symbols\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"none\">Severity and Impact<\/span><\/b><span data-contrast=\"none\">: The report should indicate the severity of the vulnerability and possible impact if left unmitigated. There are standards for this, such as a CVSS score. <\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Noto Sans Symbols\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"none\">Vulnerability Identifying Information: <\/span><\/b><span data-contrast=\"none\">To be used by the security experts in your organization. You are looking for vulnerability details from publicly available databases such as the <\/span><a href=\"https:\/\/nvd.nist.gov\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">National Vulnerability Database<\/span><\/a><span data-contrast=\"none\">. This will have IDs, severity, and information on the vulnerability.\u00a0 <\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Noto Sans Symbols\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"none\">Description:<\/span><\/b><span data-contrast=\"none\"> A summary of the vulnerability associated with an identified component.<\/span><span data-ccp-props=\"{&quot;335559685&quot;:720,&quot;335559991&quot;:360}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Now is the time to start getting more proactive in requesting SBOMs from your software vendors. This requirement is already becoming standard practice for U.S. federal government purchasing, as documented in the recent Executive Order on Cybersecurity.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">SBOMs will soon become an important decision factor in software procurement since increased visibility into products being considered may expose risks organizations are unwilling to take. Regardless of the outcome,\u00a0 SBOMs will undoubtedly help buyers improve their security and risk posture to protect their <a href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-supply-chain-erp-guide\/\" target=\"_blank\" rel=\"noopener\">supply chain organizations<\/a> proactively.\u00a0\u00a0\u00a0\u00a0 <\/span><\/p>\n<hr \/>\n<p style=\"text-align: justify;\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"third-1\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"ERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/erp-third.jpg\" alt=\"Download Link to ERP Buyer's Guide\" \/><\/a> <a class=\"third-2\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-manufacturing-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"MERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/merp-third.jpg\" alt=\"Download Link to MERP Buyer's Guide\" \/><\/a> <a class=\"third-3\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-distribution-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"DERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/derp-third.jpg\" alt=\"Download Link to DERP Buyer's Guide\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of Solutions Review\u2019s\u00a0Contributed Content Series\u2014a collection of articles written by industry thought leaders in maturing software categories\u2014Mike Dager, the Chief Executive Officer of GrammaTech, shares some insights on the enterprise security benefits that software bill of materials (SBOMs) can offer to supply chain professionals. Supply chain professionals should be familiar with a bill [&hellip;]<\/p>\n","protected":false},"author":174,"featured_media":4591,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[2181,2182,2963,2185,2186,2180,2183,2184],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0<\/title>\n<meta name=\"description\" content=\"As part of Solutions Review&#039;s Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0\" \/>\n<meta property=\"og:description\" content=\"As part of Solutions Review&#039;s Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Best ERP Software, Vendors, News and Reviews\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-18T11:26:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-01T18:08:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mike Dager\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mike Dager\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/\",\"name\":\"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg\",\"datePublished\":\"2022-05-18T11:26:56+00:00\",\"dateModified\":\"2023-08-01T18:08:52+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/401106b28758f38a57156d1a31a287e7\"},\"description\":\"As part of Solutions Review's Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg\",\"width\":800,\"height\":400,\"caption\":\"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/\",\"name\":\"Best ERP Software, Vendors, News and Reviews\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/401106b28758f38a57156d1a31a287e7\",\"name\":\"Mike Dager\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2024\/05\/Mike-Dager-CEO-GrammaTech.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2024\/05\/Mike-Dager-CEO-GrammaTech.jpg\",\"caption\":\"Mike Dager\"},\"description\":\"Mike Dager is Chief Executive Officer of GrammaTech. He has served as CEO of Bayshore Networks, Arxan Technologies, Worksoft, and OSE Systems Inc. Mike began his career at Texas Instruments in the semiconductor division.\",\"sameAs\":[\"https:\/\/www.grammatech.com\/\",\"https:\/\/www.linkedin.com\/in\/mikedager\/\"],\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/author\/mdager\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0","description":"As part of Solutions Review's Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/","og_locale":"en_US","og_type":"article","og_title":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0","og_description":"As part of Solutions Review's Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.","og_url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/","og_site_name":"Best ERP Software, Vendors, News and Reviews","article_published_time":"2022-05-18T11:26:56+00:00","article_modified_time":"2023-08-01T18:08:52+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg","type":"image\/jpeg"}],"author":"Mike Dager","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mike Dager","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/","name":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0","isPartOf":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg","datePublished":"2022-05-18T11:26:56+00:00","dateModified":"2023-08-01T18:08:52+00:00","author":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/401106b28758f38a57156d1a31a287e7"},"description":"As part of Solutions Review's Contributed Content Series, Mike Dager of GrammaTech shares some insights on the benefits that SBOMs can offer.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#primaryimage","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg","contentUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2022\/05\/How-SBOMs-Reduce-Software-Procurement-Risk-and-Improve-Enterprise-Security.jpg","width":800,"height":400,"caption":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/how-sboms-reduce-software-procurement-risk-and-improve-enterprise-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/"},{"@type":"ListItem","position":2,"name":"How SBOMs Reduce Software Procurement Risk and Improve Enterprise Security\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/","name":"Best ERP Software, Vendors, News and Reviews","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/401106b28758f38a57156d1a31a287e7","name":"Mike Dager","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2024\/05\/Mike-Dager-CEO-GrammaTech.jpg","contentUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2024\/05\/Mike-Dager-CEO-GrammaTech.jpg","caption":"Mike Dager"},"description":"Mike Dager is Chief Executive Officer of GrammaTech. He has served as CEO of Bayshore Networks, Arxan Technologies, Worksoft, and OSE Systems Inc. Mike began his career at Texas Instruments in the semiconductor division.","sameAs":["https:\/\/www.grammatech.com\/","https:\/\/www.linkedin.com\/in\/mikedager\/"],"url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/author\/mdager\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts\/4590"}],"collection":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/users\/174"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/comments?post=4590"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts\/4590\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/media\/4591"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/media?parent=4590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/categories?post=4590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/tags?post=4590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}