{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T04:09:35Z","timestamp":1781755775827,"version":"3.54.5"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031640728","type":"print"},{"value":"9783031640735","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-64073-5_20","type":"book-chapter","created":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T13:02:35Z","timestamp":1719838955000},"page":"293-304","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Understanding SBOMs in\u00a0Real-World Systems \u2013 A Practical DevOps\/SecOps Perspective"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2111-4934","authenticated-orcid":false,"given":"Narges","family":"Yousefnezhad","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2704-9715","authenticated-orcid":false,"given":"Andrei","family":"Costin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,6,30]]},"reference":[{"key":"20_CR1","doi-asserted-by":"publisher","DOI":"10.2172\/2204407","volume-title":"SoK: a framework for and analysis of software bill of materials tools","author":"A Arora","year":"2022","unstructured":"Arora, A., Wright, V.L., Garman, C.: SoK: a framework for and analysis of software bill of materials tools. Tech. rep, Idaho National Laboratory (INL) (2022)"},{"key":"20_CR2","unstructured":"Bendix, L., G\u00f6ransson, A.: A Comprehensive View of Software Bill of Materials (2023)"},{"key":"20_CR3","unstructured":"Biden, J.R.: Executive Order on Improving the Nation\u2019s Cybersecurity . https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/ (2021)"},{"key":"20_CR4","doi-asserted-by":"crossref","unstructured":"Birkholz, H., Fitzgerald-McKay, J., Schmidt, C., Waltermire, D.: RFC 9393 Concise Software Identification Tags (2023)","DOI":"10.17487\/RFC9393"},{"key":"20_CR5","unstructured":"Camp, L.J., Andalibi, V.: SboM vulnerability assessment & corresponding requirements. NTIA Res. Not. Req. Comments Softw. Bill Mater. Elem. Consid. (2021)"},{"key":"20_CR6","doi-asserted-by":"publisher","unstructured":"Chaora, A., Ensmenger, N.L., Camp, L.J.: Discourse, challenges, and prospects around the adoption and dissemination of software bills of materials (SBOMs). In: IEEE International Symposium on Technology and Society, ISTAS 2023, Swansea, United Kingdom, September 13-15, 2023, pp. 1\u20134. IEEE (2023). https:\/\/doi.org\/10.1109\/ISTAS57930.2023.10305922, https:\/\/doi.org\/10.1109\/ISTAS57930.2023.10305922","DOI":"10.1109\/ISTAS57930.2023.10305922"},{"key":"20_CR7","unstructured":"CISA: Types of Software Bill of Material (SBOM) Documents. https:\/\/www.cisa.gov\/sites\/default\/files\/2023-04\/sbom-types-document-508c.pdf (2023)"},{"key":"20_CR8","doi-asserted-by":"crossref","unstructured":"Ghanem, W.A.H., Belaton, B.: Improving accuracy of applications fingerprinting on local networks using NMAP-AMAP-ETTERCAP as a hybrid framework. In: 2013 IEEE International Conference on Control System, Computing and Engineering, pp. 403\u2013407. IEEE (2013)","DOI":"10.1109\/ICCSCE.2013.6719998"},{"key":"20_CR9","doi-asserted-by":"publisher","unstructured":"Hyeon, D.E., Park, J.H., Youm, H.Y.: A secure firmware and software update model based on blockchains for internet of things devices using SBOM. In: 18th Asia Joint Conference on Information Security, AsiaJCIS 2023, Koganei, Japan, August 15-16, 2023, pp. 53\u201358. IEEE (2023). https:\/\/doi.org\/10.1109\/ASIAJCIS60284.2023.00019","DOI":"10.1109\/ASIAJCIS60284.2023.00019"},{"key":"20_CR10","doi-asserted-by":"crossref","unstructured":"Mohan, V., Othmane, L.B.: SecDevOps: is it a marketing buzzword?-mapping research on security in DevOps. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp. 542\u2013547. IEEE (2016)","DOI":"10.1109\/ARES.2016.92"},{"key":"20_CR11","unstructured":"Muir\u00ed, \u00c9.\u00d3.: Framing software component transparency: establishing a common software bill of material (SBOM). NTIA, Nov 12 (2019)"},{"key":"20_CR12","unstructured":"NTIA: Software Suppliers Playbook: SBOM Production and Provision. https:\/\/www.ntia.gov\/sites\/default\/files\/publications\/software_suppliers_sbom_production_and_provision_-_final_0.pdf (2021)"},{"key":"20_CR13","unstructured":"NTIA: Survey of Existing SBOM Formats and Standards. https:\/\/www.ntia.gov\/files\/ntia\/publications\/ntia_sbom_formats_and_standards_whitepaper_-_version_20191025.pdf (2021)"},{"key":"20_CR14","unstructured":"NTIA: The Minimum Elements For a Software Bill of Materials. https:\/\/www.ntia.doc.gov\/files\/ntia\/publications\/sbom_minimum_elements_report.pdf (2021)"},{"key":"20_CR15","unstructured":"OWASP: Authoritative Guide to SBOM- Implement and Optimize use of Software Bill of Materials. https:\/\/cyclonedx.org\/guides\/sbom\/generation\/ (2024)"},{"key":"20_CR16","doi-asserted-by":"crossref","unstructured":"Sehgal, V.V., Ambili, P.: A taxonomy and survey of software bill of materials (SBOM) generation approaches. In: Analytics Global Conference, pp. 40\u201351. Springer (2023)","DOI":"10.1007\/978-3-031-50815-8_3"},{"key":"20_CR17","unstructured":"Shiff, L.: SecOps vs DevSecOps: What\u2019s The Difference? https:\/\/www.bmc.com\/blogs\/secops-vs-devsecops\/ (2020)"},{"key":"20_CR18","unstructured":"Synopsys: Which of CISA\u2019s Six Types of SBOMs Are Right for You? https:\/\/www.synopsys.com\/software-integrity\/resources\/ebooks\/cisa-sboms-guide.html+ (2024)"},{"key":"20_CR19","doi-asserted-by":"crossref","unstructured":"Wu, W., Wang, P., Zhao, L., Jiang, W.: An intelligent security detection and response scheme based on SBOM for securing IoT terminal devices. In: 11th International Conference on Information, Communication and Networks (ICICN), pp. 391\u2013398. IEEE (2023)","DOI":"10.1109\/ICICN59530.2023.10393435"},{"key":"20_CR20","doi-asserted-by":"publisher","unstructured":"Xia, B., Bi, T., Xing, Z., Lu, Q., Zhu, L.: An empirical study on software bill of materials: where we stand and the road ahead. In: 45th IEEE\/ACM International Conference on Software Engineering, ICSE 2023, Melbourne, Australia, May 14-20, 2023, pp. 2630\u20132642. IEEE (2023). https:\/\/doi.org\/10.1109\/ICSE48619.2023.00219, https:\/\/doi.org\/10.1109\/ICSE48619.2023.00219","DOI":"10.1109\/ICSE48619.2023.00219"}],"container-title":["Lecture Notes in Business Information Processing","Business Modeling and Software Design"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-64073-5_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,22]],"date-time":"2024-07-22T06:05:17Z","timestamp":1721628317000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-64073-5_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031640728","9783031640735"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-64073-5_20","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"value":"1865-1348","type":"print"},{"value":"1865-1356","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"30 June 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"BMSD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Business Modeling and Software Design","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg City","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 July 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"bmsd2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.is-bmsd.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}