Uploaded December 2025 | Updated September 2026, 3 weeks ago
The last two years have been a landmark period for SBOM (software bill of materials) adoption. Although a fair number of organizations have been producing SBOMs for a relatively extended period (often for specific regulatory compliance purposes), a much larger group has recently implemented broader SBOM management programs that cover a wider range of use cases.
This presentation — “SBOMs in the Real World: Practical Guidance for Three Common SBOM Scenarios” — will focus on three of these emerging areas:
1. SBOM generation and distribution to meet customer requests and new regulatory requirements
2. SBOM aggregation from internal teams and product units to facilitate centralized vulnerability management and response
3. SBOM ingestion from external software supplier networks to facilitate first- and third-party vulnerability management and response
Each section of this talk will include specific guidance to help attendees understand how SBOM programs within their organizations can more effectively manage these scenarios.
Cortez Frazier Jr.
FOSSA
Principal Product Manager
Cortez Frazier Jr. is the product lead for FOSSA’s SaaS and on-premises enterprise applications. FOSSA is a developer tool (in the software composition analysis category) for managing open source license compliance and security vulnerabilities.
Before joining FOSSA, Cortez served as product lead for all of Puppet’s SaaS-based products, primarily within the CSPM (Cloud Security Posture Management) domain.
Earlier, Cortez worked as a Senior Cybersecurity Architect for GE Power within the application security space. At GE Power, Cortez was responsible for ~1800 devs and ~600 applications and focused on building and scaling enterprise vulnerability management programs.
linkedin.com/in/cortez-frazier-jr-73712b19b
fossa.com (company)
@Done_Next (twitter.com/Done_Next)
Managed by the OWASP® Foundation
owasp.org
The last two years have been a landmark period for SBOM (software bill of materials) adoption. Although a fair number of organizations have been producing SBOMs for a relatively extended period (often for specific regulatory compliance purposes), a much larger group has recently implemented broader SBOM management programs that cover a wider range of use cases.
This presentation — “SBOMs in the Real World: Practical Guidance for Three Common SBOM Scenarios” — will focus on three of these emerging areas:
1. SBOM generation and distribution to meet customer requests and new regulatory requirements
2. SBOM aggregation from internal teams and product units to facilitate centralized vulnerability management and response
3. SBOM ingestion from external software supplier networks to facilitate first- and third-party vulnerability management and response
Each section of this talk will include specific guidance to help attendees understand how SBOM programs within their organizations can more effectively manage these scenarios.
Cortez Frazier Jr.
FOSSA
Principal Product Manager
Cortez Frazier Jr. is the product lead for FOSSA’s SaaS and on-premises enterprise applications. FOSSA is a developer tool (in the software composition analysis category) for managing open source license compliance and security vulnerabilities.
Before joining FOSSA, Cortez served as product lead for all of Puppet’s SaaS-based products, primarily within the CSPM (Cloud Security Posture Management) domain.
Earlier, Cortez worked as a Senior Cybersecurity Architect for GE Power within the application security space. At GE Power, Cortez was responsible for ~1800 devs and ~600 applications and focused on building and scaling enterprise vulnerability management programs.
linkedin.com/in/cortez-frazier-jr-73712b19b
fossa.com (company)
@Done_Next (twitter.com/Done_Next)
Managed by the OWASP® Foundation
owasp.org










