SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM Scenarios @OWASPGLOBAL
SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM Scenarios  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
The last two years have been a landmark period for SBOM (software bill of materials) adoption. Although a fair number of organizations have been producing SBOMs for a relatively extended period (often for specific regulatory compliance purposes), a much larger group has recently implemented broader SBOM management programs that cover a wider range of use cases.

This presentation — “SBOMs in the Real World: Practical Guidance for Three Common SBOM Scenarios” — will focus on three of these emerging areas:

1. SBOM generation and distribution to meet customer requests and new regulatory requirements
2. SBOM aggregation from internal teams and product units to facilitate centralized vulnerability management and response
3. SBOM ingestion from external software supplier networks to facilitate first- and third-party vulnerability management and response

Each section of this talk will include specific guidance to help attendees understand how SBOM programs within their organizations can more effectively manage these scenarios.

Cortez Frazier Jr.
FOSSA
Principal Product Manager

Cortez Frazier Jr. is the product lead for FOSSA’s SaaS and on-premises enterprise applications. FOSSA is a developer tool (in the software composition analysis category) for managing open source license compliance and security vulnerabilities.

Before joining FOSSA, Cortez served as product lead for all of Puppet’s SaaS-based products, primarily within the CSPM (Cloud Security Posture Management) domain.

Earlier, Cortez worked as a Senior Cybersecurity Architect for GE Power within the application security space. At GE Power, Cortez was responsible for ~1800 devs and ~600 applications and focused on building and scaling enterprise vulnerability management programs.
linkedin.com/in/cortez-frazier-jr-73712b19b
fossa.com (company)
@Done_Next (twitter.com/Done_Next)

Managed by the OWASP® Foundation
owasp.org
SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM ScenariosInfluencing Without Authority: The Foundations of a Successful Security Department of YesOWASP Global Board of Directors - November 2025OWASP Serverless Top 10 - David Melamed, Aruneesh SalhotraOWASP Global Board of Directors Public Board Meeting - August 2026OWASP Application Security Verification Standard (ASVS) - Shanni Prutchi, Ryan ArmstrongKeynote by Daniel Miessler: The Future of AppSec Is Continuous ContextKeynote: Nemo Resideo: Managing Application Security Through Rapid Change - Sarah-Jane MaddenASVS Testing: You Keep Using Those WordsOWASP Finance Overview PresentationAttacking AIOWASP Board of Directors 2026 Officer Elections
OWASP Foundation |

SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM Scenarios

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER