Compare an SBOM to CISA's Minimum Elements
An SBOM is more useful when students can explain what information it contains and what questions it still cannot answer.
Goal
Evaluate an SBOM as evidence about a software supply chain rather than treating its existence as proof of security.
Activity
- Obtain an SBOM from a small sample project or instructor-provided example.
- Open CISA’s 2026 Minimum Elements for a Software Bill of Materials.
- Build a two-column checklist: Present and Missing/unclear.
- Locate fields such as component identity/version, supplier or author information, relationships, hashes, licenses, generation context, and SBOM tool information when applicable.
- Pick one missing field and explain what risk or uncertainty it creates.
Deliverable
Submit the checklist and a paragraph answering: What can this SBOM support confidently, and what still requires another source or control?
Safety note
Use a classroom project or public sample. Do not upload proprietary software inventories or credentials to third-party services for this exercise.
Source material
First spotted in PTIR: August 1, 2026, Morning Briefing.
CISA’s July 2026 SBOM update expanded the minimum baseline beyond package names and versions to include fields such as component hashes, licenses, the SBOM-generation tool, and generation context. The source is valuable for teaching because students can treat an SBOM as structured evidence and ask which supply-chain questions it can—and cannot—answer.
Consult CISA’s 2026 SBOM minimum-elements resource · Official PDF