How to strengthen Supply Chain Security: Practical Exchange and Roadmap
Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.
We will examine:
- How SBOM, CSAF and VEX relate and why version-level detail matters.
- The practical value of an SBOM and why it’s increasingly required by law and IT procurement.
- How to create and consume SBOMs?
- Methods to identify dependencies in the context of vulnerabilities.
- Approaches to triage: not all vulnerabilities affect every stakeholder equally.
- Techniques to analyze vulnerabilities and identify affected products and product families.
- Sources of vulnerability information and how to map data unambiguously to products and specific software versions.
- Reporting obligations: where and how to disclose vulnerabilities.
- Tools and automation that help manage information volume and complexity.
- Technical, organizational and personnel challenges to achieving end-to-end supply chain security.
- The role of AI in supply chain security.
- How do we protect ourselves from malicious actors / infected dependencies?
- The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.
- We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.
This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.
Continue reading