The Missing Link - How we collect and leverage SBOMs - Cassie Crossley @OWASPGLOBAL
The Missing Link - How we collect and leverage SBOMs - Cassie Crossley  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
There is some debate as to how SBOMs can enhance vulnerability management practices, and some believe that collecting SBOMs from internal teams or suppliers is too difficult and time-consuming. Learn how one company has collected thousands of our product SBOMs and how we are leveraging the SBOMs as part of our corporate product CERT to quickly analyze and focus our attention when time is of importance. This presentation describes how we modified our policies and processes to collect, generate, and store thousands of SBOMs. You will hear how we have leveraged SBOMs during the Log4j and OpenSSL vulnerability events. Then we will conclude with key learnings, suggestions, and opportunities for improvement.

-

Managed by the OWASP® Foundation
owasp.org
The Missing Link - How we collect and leverage SBOMs - Cassie CrossleyAutomating Threat Modeling - Challenges + AI SolutionsRethinking Threat Modeling for Dev Teams: A Scalable ApproachLearning from Past Security Breaches: Strengthening AppSec Efforts and Focus - Jon McCoy202005 May 2020 Global Board MeetingAppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan BrätschOWASP Coraza - Web Application Firewall - Juan Pablo TossoBenchmarking Scanner Blind Spots: How Runtime Context Uncovers Hidden VulnsSecurity for Citizen Developers: Low-Code/No-Code Cybersecurity ThreatsExploiting Client-Side Path Traversal: CSRF Is Dead, Long Live CSRF - Maxence SchmittYour RPA is Mine: Complete Takeover of RPA EcosystemsNoise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2
OWASP Foundation |

The Missing Link - How we collect and leverage SBOMs - Cassie Crossley

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER