Software Bill of Materials
A structured inventory of software components and dependency relationships used to improve supply-chain transparency and vulnerability response.
Boundaries
An SBOM is an inventory and relationship record, not a vulnerability verdict. Risk analysis still requires version, exposure, exploitability, and operational context.
Related Concepts
- Software Supply Chain
- CVE
- Vulnerability Management
- Provenance
Source
- https://csrc.nist.gov/glossary/term/software_bill_of_materials