Evolving Threats and Regulations in Software Supply Chain Security
13 min read
Evolving Threats and Regulations in Software Supply Chain Security
By Eric Byres on February 13, 2024

2023 is in the rearview mirror and 2024 is now well underway. I wanted to post my thoughts on some of the software supply chain trends we saw last year and how they will continue to shape...

Continue Reading
EU Cyber Resilience Act (CRA) Clears Penultimate Step
5 min read
EU Cyber Resilience Act (CRA) Clears Penultimate Step
By Eric Byres on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European Parliament and the EU Council reached an agreement on the legislation. It...

Continue Reading
S4x23 SBOM Challenge — Part 3: VEX Document Ingestion
7 min read
S4x23 SBOM Challenge — Part 3: VEX Document Ingestion
By Derek Kruszewski on March 16, 2023

Three weeks ago I reported on the first part of the S4x23 SBOM Challenge run by Idaho National Laboratory (INL), which focused on SBOM Creation. Last week I reported on the second part:...

Continue Reading
S4x23 SBOM Challenge — Part 2: SBOM Ingestion
7 min read
S4x23 SBOM Challenge — Part 2: SBOM Ingestion
By Derek Kruszewski on March 8, 2023

Two weeks ago I reported on the first part of the SBOM Challenge at the S4x23 cybersecurity conference in Miami, Florida. The Day 1 goal was for each team to create an accurate SBOM for...

Continue Reading
S4x23 SBOM Challenge — Part 1
10 min read
S4x23 SBOM Challenge — Part 1
By Derek Kruszewski on February 24, 2023

The aDolus Team has just returned from participating in the SBOM Challenge at the S4x23 cybersecurity conference in Miami, Florida. This blog is the first of a series reporting on what we...

Continue Reading
A Flurry of Regulatory Action and the Need for SBOMs
5 min read
A Flurry of Regulatory Action and the Need for SBOMs
By Eric Byres on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a series of regulatory initiatives that government agencies (and anyone...

Continue Reading
Sorry Blackberry: You Are Part of the Supply Chain
2 min read
Sorry Blackberry: You Are Part of the Supply Chain
By Eric Byres on November 2, 2021

Today, reporters Betsy Woodruff Swan and Eric Geller at Politico published a story: “BlackBerry resisted announcing major flaw in software powering cars, hospital equipment.” They outline...

Continue Reading
What is VEX and What Does it Have to Do with SBOMs?
3 min read
What is VEX and What Does it Have to Do with SBOMs?
By Derek Kruszewski on August 12, 2021

Recently, we have been fielding many inquiries here at aDolus regarding “VEX.” If you are not familiar with this mysterious abbreviation, you’ve fortunately landed in the right place....

Continue Reading
NTIA Publishes Minimum Components of an SBOM
4 min read
NTIA Publishes Minimum Components of an SBOM
By Derek Kruszewski on July 15, 2021

In today’s blog post I’d like to recognize all the hard work done by NTIA (National Telecommunications and Information Administration) and congratulate them on publishing the minimum...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
5 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
By Eric Byres on May 26, 2021

Section 3 - Less Fog, More Cloud Section 3: Modernizing Federal Government Cybersecurity of the Executive Order is all about government agencies moving to the cloud and doing it right. If...

Continue Reading
Loading more posts
No more posts to load
1 2

Stay up to date