SECAI Core · phase 12 of 15 · noun

Software bill of materials

Inventory of third-party and open-source code components used in an application or package.

The Explain card

Plain English
An SBOM is a formal inventory of the third-party and open-source components used in an application or package, including versions, so anyone can see exactly what the software is made of.
Example
When a critical flaw is announced in a widely used library, a team with an SBOM for its AI platform answers "are we affected?" in minutes instead of days of digging through builds.
Why it matters
You cannot patch what you cannot see. For AI systems an SBOM increasingly extends to models and datasets, giving defenders a map of every inherited risk.
Hook
The nutrition label on the side of your software.

Word knowledge

How the word is built, where it came from, and what it sits beside in memory.

In a sentence

The security team checked the software bill of materials to locate every package containing the vulnerable Log4j library.

Why these words
  • software English soft plus ware, coined by contrast with hardware marks the phrase as belonging to computer programs
  • bill Anglo-French bille, a written document or list serves as the head noun for a formal list
  • of Old English of links the formal list to what it records
  • materials Latin materia through Old French materiel names the listed items collectively and remains plural
Where it came from
Origin
English compound modeled on the manufacturing phrase bill of materials
Entered the language
21st century
What changed
A manufacturing expression for documenting constituent parts was transferred to software engineering and commonly shortened to SBOM.
How it is spelled
Pattern
software is written as a closed compound
Pattern
bill of materials retains the plural form materials
Pattern
the initial letters form the abbreviation SBOM

Spelled like

  • hardware
  • firmware
  • table of contents
  • list of ingredients
Broken into chunks
  • soft
    • soften
    • softness
  • ware
    • hardware
    • firmware
  • materi
    • material
    • materialize
What it sits beside

Same subject

  • software supply chain
  • dependency scanning
  • vulnerability management
  • package repository

Same shape

  • hardware bill of materials
  • manufacturing bill of materials

software supply chain records

  • software bill of materials
  • dependency manifest
  • lockfile

initialisms used in application security

  • SBOM
  • SAST
  • DAST

Where it sits in the deck

Phase 12: Defensive Technologies and Secure Development Practices

Map defenses directly to the attacks just cataloged — the technical controls, secure coding practices, and protective tools that harden AI and traditional systems alike.