SBOMs in Action: Security & Compliance (LFWS302)
This one-day course introduces you to software bills of materials (SBOMs) and shows how to put them to work for security and compliance.
Suggested prerequisites: a basic understanding of software development, familiarity with command-line interfaces, basic DevOps or CI/CD knowledge, and a general awareness of software security concepts.
Audience: DevSecOps specialists, developers, engineers, compliance professionals and team leads.
With the EU Cyber Resilience Act (CRA) asking for greater transparency about what goes into software, knowing your way around SBOMs is a practical way to improve visibility and reduce supply chain risk. This course is made for people who want to deepen their security expertise, support compliance and show leadership in software supply chain integrity.
You will learn to generate and validate SBOMs in both the SPDX and CycloneDX formats, and to compare how accurate they are across different build environments. You will see how to integrate SBOM generation into CI/CD pipelines for more visibility and automation, how to interpret dependencies, licenses and vulnerabilities, and how to explain your findings clearly to management and stakeholders. Along the way you will also look at what achieving compliance with the CRA involves.
Every topic comes with a hands-on lab, from interpreting a sample SBOM to automating SBOM generation and remediation in a CI pipeline and creating a simple compliance report that you present. You leave with practical SBOM skills that strengthen secure development and prepare you for leadership in software delivery and compliance under new requirements such as the CRA.