From JSON to Clarity: Practical Tools for SBOM Interpretation @FIRSTdotorg
From JSON to Clarity: Practical Tools for SBOM Interpretation  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 5 hours ago
John Bergland (IBM, US), Zadia Alden (Supply Chain Manager, GB)

SBOMs are critical for software supply chain security, but their complexity often limits their value beyond engineering teams. Business leaders frequently ask: “Why isn’t this human-readable?” or “Is this all open source?”—revealing a gap between technical detail and business understanding. This session demonstrates how to bridge that gap using lightweight, web-based tools enhanced with AI. Built without advanced programming skills, these tools transform raw SBOM data into clear, actionable insights for both technical and non-technical audiences. By demystifying SBOMs, this approach empowers organizations to improve compliance, risk management, and collaboration across technical and business teams—without requiring deep technical expertise. Attendees will see six practical tools in action, each designed to answer critical questions about SBOM quality and security posture:

SBOM Validator: Confirms compliance with CycloneDX/SPDX standards. - Completeness Checker: Verifies NTIA minimum elements.
Component Analyzer: Distinguishes open source vs. proprietary components.
CVE Mapper: Detects known vulnerabilities across supplier SBOMs.
Version Drift Analyzer: Highlights outdated components and upgrade priorities.
Scan Readiness Checker: Flags issues that could impact downstream vulnerability scanning. These tools accelerate SBOM interpretation, reduce manual effort, and provide actionable insights that can integrate into CI/CD pipelines and supplier risk assessments. Attendees will leave with practical strategies and examples of how automation and AI can make SBOMs more transparent and useful across the organization.
Session Takeaways:

Understand why SBOM complexity creates barriers for both technical and business teams.
Learn practical strategies to make SBOMs accessible without sacrificing technical rigor.
Explore six lightweight tools that validate, analyze, and enrich SBOM data.
Gain actionable ideas for integrating SBOM insights into CI/CD and supplier risk assessments.
Discover how automation and AI accelerate SBOM adoption and compliance.

---

John Bergland is based in Boston, Massachusetts and works as a Program Manager for Supply Chain Security at IBM Office of the CISO. He currently specializes in working with SBOMs, helping to define and scale IBM’s process for both analyzing and producing SBOMs. During his career at IBM, he has worked as a business analyst and requirements engineer. He has an MBA and Masters in Information Systems from Boston University.

Zadia Alden is based in Winchester, England. She has over 25 years' experience in Software Development, performing various different roles over those years. In her current role, she manages the Open-Source Program Office within the CISO organisation. Over the last couple of years, she has been working in the SBOM space, building her expertise to become an SME in SBOM generation and analysis. She is a Certified Project Management Professional, within the Project Management Institute.
From JSON to Clarity: Practical Tools for SBOM InterpretationVersus KillnetDeriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring MethodUnmasking Cyber Security: Rethinking Small to Medium Business Security AwarenessFrom Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...From CVD to Secure Releases: Automating Security from Source to ReleasesOnly Seeing Stars: Enabling the Open Source Scripting Community with OCSFInside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chairDraugnet: Anonymous Threat Reporting That Actually WorksAutomated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?
FIRST |

From JSON to Clarity: Practical Tools for SBOM Interpretation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER