• Home
  • Search
  • Secure Supply Chain Management in DevOps: Addressing Software Bill of Materials (SBOM) Risks
  • https://doi.org/10.63282/3050-922x.ijeret-v6i2p115Copy DOI Icon

Secure Supply Chain Management in DevOps: Addressing Software Bill of Materials (SBOM) Risks

  • Abstract
  • Literature Map
  • Similar Papers
Abstract

The software supply chain has become one of the most actively exploited attack surfaces in enterprise technology, and the events of the past four years have transformed what was once a theoretical concern into a documented operational reality. The Software Bill of Materials a structured inventory of every component, library, and dependency that comprises a software artifact has emerged as the foundational mechanism for supply chain risk visibility. Yet generating an SBOM is only the beginning of the challenge. Using it effectively, keeping it accurate, integrating it into active DevOps workflows, and deriving security decisions from it at pipeline speed requires an architectural and organizational investment that most organizations have not yet made. This paper examines how fourteen engineering organizations approached SBOM generation, management, and operationalization across a nineteen-month study period from April 2023 through October 2024. We analyze SBOM completeness rates, pipeline integration depth, vulnerability-to-remediation lead times using SBOM-informed workflows, and the organizational barriers that most consistently limit SBOM program effectiveness. Results demonstrate that organizations with mature SBOM integration reduce known-vulnerability exposure windows by an average of 71% compared to those relying on traditional reactive scanning approaches. We propose a five-stage SBOM maturity model and offer practical guidance for security and DevOps practitioners navigating the transition from SBOM generation to SBOM operationalization.

Similar Papers
  • Research Article
  • Citations9

Building a Secure Software Supply Chain with GNU Guix

  • Jun 15, 2022
  • The Art, Science, and Engineering of Programming
  • Ludovic Courtès
  • Conference Article
  • Citations3

Research on the Application of Blockchain Smart Contract in Software Supply Chain Management

  • Dec 01, 2022
  • Shuaijianni Xu +2
  • Book Chapter
  • Citations2

Information Quality in Supply Chain Software

  • Jan 01, 2016
  • Farhad Kafi +1
  • Conference Article
  • Citations14

Estimating the Attack Surface from Residual Vulnerabilities in Open Source Software Supply Chain

  • Dec 01, 2021
  • Dapeng Yan +5
  • Research Article
  • Citations10

Collaboration and Teaming in the Software Supply Chain

  • Jan 01, 2005
  • Supply Chain Forum: An International Journal
  • Christopher L Tucci +3
  • Research Article
  • Citations5

Supply chain risk and security management: an interpretive structural modelling approach

  • Jan 01, 2012
  • International Journal of Logistics Economics and Globalisation
  • Anjali Saxena +1
  • Research Article
  • Citations23

A coordination mechanism for supply chains with capacity expansions and order-dependent lead times

  • Feb 20, 2020
  • European Journal of Operational Research
  • Christoph H Glock +2
  • Research Article

Evaluation of Blockchain Technology for Supply Chains using an Integrated Fuzzy Cognitive Map-QFD Methodology

  • Jun 25, 2024
  • Journal of Advanced Research in Natural and Applied Sciences
  • Ayça Maden +1
  • Research Article
  • Citations1

Cadeias de Suprimentos “Leagile” e a Geração de Valor

  • Oct 13, 2014
  • Organizações e Sustentabilidade
  • Ernani Carpenedo Busanelo
  • Research Article
  • Citations78

LT variance or LT mean reduction in supply chain management: Which one has a higher impact on SC performance?

  • Dec 24, 2009
  • International Journal of Production Economics
  • S Kamal Chaharsooghi +1
  • Research Article
  • Citations6

Corporate Portals for Supply Chain Collaboration

  • Nov 22, 2005
  • Journal of Internet Commerce
  • Scott Paquette +1
  • Research Article
  • Citations167

Involvement of controllable lead time and variable demand for a smart manufacturing system under a supply chain management

  • Jun 24, 2021
  • Expert Systems with Applications
  • Bikash Koli Dey +2
  • Research Article
  • Citations70

Evaluation of cycle-count policies for supply chains with inventory inaccuracy and implications on RFID investments

  • Feb 06, 2014
  • European Journal of Operational Research
  • A Gürhan Kök +1
  • Conference Article

Supply Chain Decision Based on Lead Time Cost Sharing Model

  • May 11, 2012
  • Jingshi He
  • Conference Article

AN ADVANCED MANUFACTURING SUPPORTED SUPPLY CHAIN – EDUCATIONAL CASE STUDIES

  • Jan 01, 2023
  • Philip Sewell +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.