Session
Integrating SBOM for Secure DevOps
The rapid acceleration of software delivery, enabled by DevOps practices, must be coupled with a robust strategy for managing software supply chain risk. A Software Bill of Materials (SBOM) is the foundation of this strategy, providing transparency into application components, dependencies, and their licenses and vulnerabilities. However, manual SBOM generation is impractical in a high-velocity environment. This talk will demonstrate the critical importance of seamlessly integrating SBOM generation into every stage of the DevOps pipeline. Attendees will learn how to leverage CycloneDX, an industry-leading standard and format, to automate the continuous gathering of comprehensive and accurate component data. Furthermore, we will explore practical open-source and commercial tooling that consumes CycloneDX output to provide actionable, real-time visualizations for security, compliance, and engineering teams, enabling rapid risk assessment and remediation. By the end of this session, attendees will have a clear roadmap for transforming their security posture from reactive vulnerability scanning to proactive supply chain risk management.
Tim Rayburn
Vice President of Consulting at Improving
Plano, Texas, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top