• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Tracking device maker Pebblebee teams with ski company on embedded tech to help locate gear – Startup

March 21, 2023

Huawei FreeBuds 5i review

March 21, 2023

Meta Is Being Sued in Kenya, Again

March 21, 2023
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    Samsung’s One UI 5 update is largely about personalization

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Security»Forget SBOM, DevSecOps teams need PBOM to stop cyber attacks 
Security

Forget SBOM, DevSecOps teams need PBOM to stop cyber attacks 

September 29, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Forget SBOM, DevSecOps teams need PBOM to stop cyber attacks 
Share
Facebook Twitter LinkedIn Pinterest Email

Were you unable to attend Transform 2022? Check out all of the summit sessions in our on-demand library now! Watch here.


Software supply chain security is one of those concerns that won’t go away. With software supply chain attacks increasing 300% in 2021, it’s clear that organizations not only have to worry about the vulnerabilities in their own environments, but those that reside within the systems of trusted suppliers too. 

In light of Biden’s executive order in May 2021, many organizations are looking to build Software Bill of Materials (SBOM) to take inventory of their environments and increase transparency over potential vulnerabilities to avoid compliance liabilities. Yet end-to-end software supply chain security platform provider, OX Security argues this isn’t enough. 

OX Security, which today announced it has raised $34 million, claims to have created a new open standard, the Pipeline Bill of Materials (PBOM), which not only inventories the code of the final product, but also the procedures and processes that contributed to the software’s development. 

For enterprises, PBOM has the potential to secure the development pipeline from end-to-end, through planning to deployment and production, monitoring each stage of the development lifecycle to identify vulnerabilities in the software supply chain. 

Event

MetaBeat 2022

MetaBeat will bring together thought leaders to give guidance on how metaverse technology will transform the way all industries communicate and do business on October 4 in San Francisco, CA.

Register Here

So how does PBOM work? 

OX Security’s approach to PBOM centers around a platform that can connect to an organization’s code repository, scanning the environment to take inventory of everything from the first line of code produced to production. 

See also  How cybersecurity vendors are misrepresenting zero trust

In practice, this involves mapping assets, apps, and pipelines, identifying what security tools are in use, while highlighting any security issues found, and prioritizing their remediation based on severity.

One of the key underlying principles of PBOM is automation, and offering users automatic fixes and remediations so they can address security issues at scale. 

“Most security teams are severely understaffed, don’t have proper visibility, and have a large backlog of issues that they struggle to prioritize and address. You end up with dev tools and processes that are outside of the control and ownership of the security teams – Shadow Dev and DevOps,” said Co-Founder and CEO of OX Security, Neatsun Ziv. 

“This leaves the software supply chain exposed to risks and security teams do not have the visibility, context or automation necessary to ensure the security and integrity of every build at scale,” Ziv said. 

By maintaining continuous visibility developers can prioritize addressing the most important risks in the software supply chain and ensure the security of CI/CD elements like code repos, build servers, and artifact registry.

The SBOM market 

OX Security is mainly computing against organizations that provide a way to generate SBOMs. 

One of the provider’s main competitors is Legit Security , which offers a platform with risk scoring for CI/CD pipelines. The platform offers the ability to automatically discover SDLC assets, dependencies and pipeline flows, to display them in graph form and offer a complete software inventory. 

At the start of this year, Legit Security announced raising $30 million as part of a Series A funding round. 

See also  Ransomware assaults drop 34% in Q2, however specialists warn of potential 'uptick'

Another competitor is Apiiro, with Apiiro Risk Assessment, which enables the user to build an application inventory, automated risk assessment questionnaires they can use to assess the security of the software supply chain. 

Aiiro’s solution can also automatically identify and prioritize risks such as design flaws, code secrets, IaC misconfigurations and exploitable APIs. The company most recently announced raising $35 million as part of a Series A funding round in 2020. 

The main differentiator between OX Security’s platform and these competitors is its focus on PBOM. 

“Most tools generate SBOMs – which may be sufficient for compliance in the future. But our mission is to prevent attacks across the software supply chain and consuming an SBOM is not enough to ensure the security and integrity of each build,” Ziv said.

Source link

attacks Cyber DevSecOps forget PBOM SBOM stop teams
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Tracking device maker Pebblebee teams with ski company on embedded tech to help locate gear – Startup

March 21, 2023

How To Boost Your Team’s Autonomy—And Why You Should

February 13, 2023

Microsoft Teams CVP joins UiPath; Sage Bionetworks names president; and more – Startup

January 12, 2023

A new firm founded by ex-Boeing leaders aims to boost health startups with diverse teams – Startup

December 27, 2022
Add A Comment

Comments are closed.

Editors Picks

The Outlast Trials’ closed beta will run over Halloween weekend

September 4, 2022

45% of companies failing to detect legal ‘ghosts’

July 26, 2022

Nubank adds Adrian Cockcroft as tech advisor

September 12, 2022

Your Side Hustle Success Begins With Finding The Money

September 19, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Tracking device maker Pebblebee teams with ski company on embedded tech to help locate gear – Startup

Huawei FreeBuds 5i review

Meta Is Being Sued in Kenya, Again

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2023 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.