Thanks Bob, got this one.
    On Monday, June 29, 2026 at 10:16:51 a.m. EDT, Martin, Robert A via 
lists.spdx.org <[email protected]> wrote:  
 
   
Hi Everyone,
 
Recently a colleague and I published the paper "Leveraging SBOMs Throughout the 
Enterprise SDLC" that examines how enterprises can leverage SBOMs throughout 
the full Software Development Lifecycle (SDLC) to support risk-informed 
decision-making, continuous monitoring, operational resilience, and regulatory 
compliance. Using a hypothetical enterprise named ACME, this paper walks 
through each SDLC phase—plan, design, implement, test, deploy, and maintain—and 
demonstrates how SBOM information can be generated, enriched, managed, and 
operationalized over time. 
 
Practical examples based on SPDX 3.0.1 illustrate how organizations can capture 
software requirements, provenance, build information, third-party dependencies, 
licensing data, vulnerability information, and lifecycle relationships in 
machine-readable form. 
 
The direct link to the pdf is 
<https://www.mitre.org/sites/default/files/2026-05/PR-25-01520-39-leveraging-sboms_throughout-the-enterprise-sdlc.pdf>
 
Bob
 -- 
Robert (Bob) Martin
Sr. Software and Supply Chain Assurance Principal Eng.
Cyber Integration and Innovation Cell Department
Cyber Engineering Division
Center for AI, Cyber & Digital
MITRE Technology & Engineering
MITRE Corporation
781-271-3001o
781-424-4095c   


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#1524): https://lists.spdx.org/g/Spdx-outreach/message/1524
Mute This Topic: https://lists.spdx.org/mt/120030915/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-outreach/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to