Thanks Bob, got this one.
On Monday, June 29, 2026 at 10:16:51 a.m. EDT, Martin, Robert A via
lists.spdx.org <[email protected]> wrote:
Hi Everyone,
Recently a colleague and I published the paper "Leveraging SBOMs Throughout the
Enterprise SDLC" that examines how enterprises can leverage SBOMs throughout
the full Software Development Lifecycle (SDLC) to support risk-informed
decision-making, continuous monitoring, operational resilience, and regulatory
compliance. Using a hypothetical enterprise named ACME, this paper walks
through each SDLC phase—plan, design, implement, test, deploy, and maintain—and
demonstrates how SBOM information can be generated, enriched, managed, and
operationalized over time.
Practical examples based on SPDX 3.0.1 illustrate how organizations can capture
software requirements, provenance, build information, third-party dependencies,
licensing data, vulnerability information, and lifecycle relationships in
machine-readable form.
The direct link to the pdf is
<https://www.mitre.org/sites/default/files/2026-05/PR-25-01520-39-leveraging-sboms_throughout-the-enterprise-sdlc.pdf>
Bob
--
Robert (Bob) Martin
Sr. Software and Supply Chain Assurance Principal Eng.
Cyber Integration and Innovation Cell Department
Cyber Engineering Division
Center for AI, Cyber & Digital
MITRE Technology & Engineering
MITRE Corporation
781-271-3001o
781-424-4095c
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#1524): https://lists.spdx.org/g/Spdx-outreach/message/1524
Mute This Topic: https://lists.spdx.org/mt/120030915/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-outreach/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-