Software Bill of Materials - Manage the Enterprise Attack Surface
foreign [Music] bill of material or s-bomb is a machine readable inventory of the third-party components used in software products in your environment as well as the supply chain relationships between them it's important for organizations to understand their s-bombs because it allows them to mitigate risks posed by vulnerabilities in things like open source software these servicenow s-bomb workspace Imports bomb files and organizes the information in a way that easily presents the risk exposure to the environment and allows organizations to quickly mitigate the risks to begin we need to import bomb files into the s-bomb workspace this can be done both automatically via an API CI CD tools like Jenkins are an example of this and manually by clicking the upload bomb button and importing a spreadsheet moving on to the home screen we're presented with information about the different entities now it's worth noting that s-bomb isn't just about homegrown applications we can also upload bombs for commercial applications containers libraries firmware Frameworks and more we're presented a list of the bomb entities which gives us information about when they're uploaded the number of Open Source components any vulnerabilities and Avis that were created now there could be hundreds if not thousands of vulnerabilities that are associated with bombs but if everything is a critical vulnerability then nothing is Avis are a way for organizations to automatically create findings for the most critical vulnerabilities to the organization itself which will then allow them to take action on those first clicking on one of these entities we see that the application is dependent on all of these open source libraries we also see the version the group the license under which it's available and the package URL which is a unique identifier we want to know which vulnerabilities are known for this application and here we can see details about the vulnerability including the cve attack vectors and what skill level is required to exploit the vulnerability when we create findings for high-risk vulnerabilities on Crown Jewel applications for example we can see them here this includes information like the risk score risk rating what their disposition is remediation Target date and to whom they're been assigned under the component list we can see every component that's being used in the environment their versions how many bomb applications are using the component and more by sorting bomb entity count we can see the top components used in the environment s-bomb helps to surface all of the relevant information to organizations to help them understand their overall risk the s-bomb workspace can also be used to track down zero day vulnerabilities we can search to quickly see how many bomb entities are using a vulnerable component using information provided in a zero day security advisory let's look at our old friend log4j we can immediately see that there are three applications using the component this gives the organization a quick and easy way to understand what their risk exposure is instead of scrambling to find the different places where a vulnerable component might be exposed lastly let's look at how we can create the findings to meet your specific criteria the creation rules help organizations prioritize what's most critical to them so for example we can build a rule to automatically create findings for components like log4j that are on critical applications this allows the organizations to really hone in on what's most at risk to them with the servicenow software bill of materials workspace organizations like yours can be empowered to more effectively manage their risk exposure and this is all built on the power of the servicenow platform if you'd like to learn more please visit us at www.servicenow.com thank you
https://www.youtube.com/watch?v=baDQw2Uocks