Software Supply Chain Security and SBOM Management

Course Category : Risk Management

An advanced programme for understanding software supply chain risks, governing dependencies, and managing SBOMs to strengthen security visibility, compliance, and cyber resilience.
Duration: 5 Days
Level: Advanced

Introduction

Modern organisations increasingly depend on open-source software, third-party libraries, packages, development frameworks, and externally supplied components. Consequently, application security can no longer focus exclusively on internally developed code; vulnerabilities and compromised dependencies can propagate through interconnected software supply chains and create significant enterprise exposure.
This course examines advanced principles of Software Supply Chain Security and Software Bill of Materials (SBOM) Management, focusing on component visibility, dependency risk, software integrity, SBOM governance, vulnerability management, and compliance requirements. Participants develop a structured understanding of the governance and security controls required to establish transparent and resilient software ecosystems..

Targeted Audience

  • Cybersecurity Professionals
  • Application and Software Security Specialists
  • DevSecOps and Secure SDLC Professionals
  • IT and Cybersecurity Managers
  • Vulnerability and Technology Risk Professionals
  • Governance, Risk, and Compliance Officers
  • Software and Systems Architects
  • Technology Procurement and Third-Party Risk Professionals

Targeted Skills

  • Software Supply Chain Risk Analysis
  • SBOM Structure and Use-Case Understanding
  • Critical Component and Dependency Identification
  • Open-Source and Third-Party Software Risk Assessment
  • SBOM-Driven Vulnerability and Risk Management
  • Software Component Governance
  • Software Integrity and Provenance Management
  • Compliance and Software Transparency

Expected Outcomes

  • Explain software supply chain security architecture and associated risk sources.
  • Interpret SBOM concepts, components, and cybersecurity use cases.
  • Distinguish direct components from transitive dependencies and assess their risk implications.
  • Evaluate security risks associated with open-source and third-party software.
  • Connect SBOM information with vulnerability management and security prioritisation.
  • Define governance controls for software components throughout their lifecycle.
  • Support software integrity, provenance, and authenticity assurance.
  • Establish an enterprise approach to SBOM management supporting compliance and cyber resilience.

Training Topics Index

  • Software supply chain structure, stakeholders, and critical components
  • Threat sources and exposure points across the software lifecycle
  • Open-source and external component security risks
  • Dependency, package, and supplier-related attack risks
  • Governance and trust principles across software development ecosystems

  • SBOM concepts and the role of software transparency
  • Core data elements and component information within an SBOM
  • Direct and transitive dependencies and component relationships
  • Common SBOM formats SPDX and CycloneDX
  • SBOM lifecycle, versioning, maintenance, and update requirements

  • Correlating SBOM components with vulnerability intelligence
  • Component exposure and vulnerability analysis
  • Risk prioritisation based on severity, exposure, and context
  • Managing obsolete, unsupported, and vulnerable components
  • Using SBOM information to support vulnerability and incident response

  • Component integrity and software provenance principles
  • Dependency manipulation and component compromise risks
  • Digital signatures and software provenance concepts
  • Component acceptance policies and security exception management
  • Organisational accountability and software supplier risk governance

  • Establishing an enterprise SBOM management policy
  • SBOM requirements within procurement and supplier relationships
  • Integrating SBOM information into governance and risk management
  • Software supply chain security performance indicators
  • Developing a roadmap for security maturity and resilience

Course Features

  • Updated and Interactive Content
  • Hypothetical Examples and Case Studies
  • Pre- and Post-assessments to Measure Impact
  • Verified Certificate with a QR Verification Code