VMware Achieves SBOM Compliance for Over 100 Services with Endor Labs
Blog post from Endor Labs
VMware successfully achieved SBOM compliance for over 100 services by collaborating with Endor Labs to develop a scalable and efficient process that manages and verifies Software Bill of Materials (SBOMs) across their vast software ecosystem. Following the release of Executive Order 14028, VMware's Global InfoSec Compliance team faced the challenge of establishing a centralized system for collecting and attesting SBOMs from both internal business units and external vendors. Endor Labs was chosen for its ability to generate and annotate Vulnerability and Exploitability eXchange (VEX) documents, which provide critical insights into vulnerabilities associated with SBOMs, enabling VMware to prioritize and address risks effectively. The integration of Endor Labs into VMware's development workflow ensures continuous monitoring and validation of SBOMs, enhancing their security posture and offering the necessary transparency and assurance for stakeholders and executives. This partnership not only facilitates risk assessment and compliance but also improves efficiency by allowing the team to quickly identify and remediate potential security gaps.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.