Course Overview

The U.S. Presidential Executive Order (EO) published on May 12, 2021, was a call to strengthen the security of the nation’s software supply chain in response to the supply chain attack on SolarWinds. Among the requirements in the EO is a requirement for vendors to provide a Software Bill of Materials (SBOMs) for all software sold to the Federal Government. This requirement in the EO is already popularizing SBOM generation across the software industry.

SBOMs provide software transparency, software integrity, and software identity benefits. Here is a bit about each:

  • Software Transparency: SBOMs provide a list of ingredients used in the creation of software, such as open-source software (OSS), components, and potentially even build tools. This enables producers and consumers to better inventory and evaluates license and vulnerability risk.
  • Software Integrity: While code signing is still the industry standard for trusting software and its integrity, SBOMs contain package and file checksums to enable software consumers to validate the hashes, which can be useful in scenarios when signatures aren’t present.
  • Software Identity: When vulnerabilities (CVEs) are created, they are assigned to a Common Platform Enumeration (CPE) identifier. An example is “Microsoft Office 365” as the identity for the software that a CVE impacts. However, this is not specific enough and the industry is interested in moving away from CPEs – and SBOMs (and the unique software identifiers within) are well positioned to better serve as a more accurate form of software identity.

What You Will Learn

  • Understand the purpose of an SBOM and regulatory requirements
  • Familiarize with Threat landscape and how SBOMs help in the same.
  • Learn how to interact with an SBOM
  • Understand how to generate an SBOM
  • Learn How to leverage an SBOM to improve vulnerability management and incident response

Program Curriculum

  • Background and Regulatory Requirements
  • Diving Into SBOM Content
  • SBOM Generation Considerations
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Quiz

  • Demo of SBOM Generation at Build-Time
  • SBOM Distribution Scenarios
  • Advanced SBOM Generation Scenarios
  • Quiz

  • Open-Source Software (OSS) Threats
  • SBOMs and Vulnerabilities
  • Vulnerability Exploitability, and Responding to an Incident
  • Quiz

  • Supply Chain Threats and Signing SBOMs
  • The Role of SBOMs in Securing the Software Supply Chain
  • Quiz

Instructor

Adrian V. Diglio

Adrian Diglio is the Principal PM Manager of the Secure Software Supply Chain team at Microsoft. He drives the central strategy for securing Microsoft’s software supply chain end-to-end, and the Software Bill of Materials (SBOMs) is one piece of that overall strategy. As such, he helped lead the SBOM implementation at scale across Microsoft using the Software Package Data Exchange (SPDX) ISO Standard specification. He’s authored two Microsoft blog posts about generating SBOMs at Microsoft, and open sourcing their SBOM Tool. Prior to the U.S. Presidential Executive Order 14028, he and other Microsoft representatives worked with the Consortium for Information and Software Quality (CISQ) Tool-to-Tool SBOM industry working group, where he led the development of the vulnerability schema sub-group. The Tool-to-Tool SBOM working group later merged with SPDX to form the basis of SPDX 3.0 next-generation specification, and he’s been engaged in SPDX’s weekly and monthly working groups ever since. Then, in response to the U.S. Presidential Executive Order, he led the internal initiative to ensure that Microsoft software-generated SBOMs to conform their requirements and worked with teams across Microsoft to implement the tool into different build environments, drive compliance across the company, and develop the SBOM tooling specifications to support a wide variety of scenarios. He has a BA from California Polytechnic University Pomona and an MBA from San Diego State University (SDSU). He has numerous professional certifications, including Security+, CISSP, GCED, PMP, and OSWP.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8