SECAI Core · phase 12 of 15 · noun
Software bill of materials
Inventory of third-party and open-source code components used in an application or package.
The Explain card
- Plain English
- An SBOM is a formal inventory of the third-party and open-source components used in an application or package, including versions, so anyone can see exactly what the software is made of.
- Example
- When a critical flaw is announced in a widely used library, a team with an SBOM for its AI platform answers "are we affected?" in minutes instead of days of digging through builds.
- Why it matters
- You cannot patch what you cannot see. For AI systems an SBOM increasingly extends to models and datasets, giving defenders a map of every inherited risk.
- Hook
- The nutrition label on the side of your software.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The security team checked the software bill of materials to locate every package containing the vulnerable Log4j library.
Why these words
- software English soft plus ware, coined by contrast with hardware marks the phrase as belonging to computer programs
- bill Anglo-French bille, a written document or list serves as the head noun for a formal list
- of Old English of links the formal list to what it records
- materials Latin materia through Old French materiel names the listed items collectively and remains plural
Where it came from
- Origin
- English compound modeled on the manufacturing phrase bill of materials
- Entered the language
- 21st century
- What changed
- A manufacturing expression for documenting constituent parts was transferred to software engineering and commonly shortened to SBOM.
How it is spelled
- Pattern
- software is written as a closed compound
- Pattern
- bill of materials retains the plural form materials
- Pattern
- the initial letters form the abbreviation SBOM
Spelled like
- hardware
- firmware
- table of contents
- list of ingredients
Broken into chunks
-
soft
- soften
- softness
-
ware
- hardware
- firmware
-
materi
- material
- materialize
What it sits beside
Same subject
- software supply chain
- dependency scanning
- vulnerability management
- package repository
Same shape
- hardware bill of materials
- manufacturing bill of materials
software supply chain records
- software bill of materials
- dependency manifest
- lockfile
initialisms used in application security
- SBOM
- SAST
- DAST
Where it sits in the deck
Phase 12: Defensive Technologies and Secure Development Practices
Map defenses directly to the attacks just cataloged — the technical controls, secure coding practices, and protective tools that harden AI and traditional systems alike.