Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[JFYI] BSI TR-03183-2 v2.0.0 was published #329

Open
fvsamson opened this issue Oct 3, 2024 · 5 comments · Fixed by #354
Open

[JFYI] BSI TR-03183-2 v2.0.0 was published #329

fvsamson opened this issue Oct 3, 2024 · 5 comments · Fixed by #354
Assignees

Comments

@fvsamson
Copy link
Contributor

fvsamson commented Oct 3, 2024

It might be of interest for you that BSI TR-03183-2 "SBOM" v2.0.0 was published along with community drafts of part 1 ("General Requirements") and part 3 ("Vulnerability Reports and Notifications"): https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html
Short link URL: https://www.bsi.bund.de/dok/TR-03183-en

Side note: The corresponding links with German web page text; the documents are all in English (i.e., all the same).
https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html
Short link URL: https://www.bsi.bund.de/dok/TR-03183


P.S.: Only loosely related, but maybe also worth reading is BSI's generic web page on CSAF and the BSI TR-03191 "CSAF".

  1. Generic web page on CSAF: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Industrielle-Steuerungs-und-Automatisierungssysteme/CSAF/CSAF_node.html
    Short link URL: https://www.bsi.bund.de/dok/en_csaf
  2. TR-03191: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03191/TR-03191_node.html
    Short link URL: https://www.bsi.bund.de/dok/TR-03191-en
    With German landing pages:
    1. Generic web page on CSAF: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Industrielle-Steuerungs-und-Automatisierungssysteme/CSAF/CSAF_node.html
    2. TR-03191: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03191/TR-03191_node.html
    Short link URL: https://www.bsi.bund.de/dok/TR-03191

HTH.
@riteshnoronha
Copy link
Contributor

@fvsamson awesome will readup and update the tool accordingly

@surendrapathak
Copy link
Collaborator

@fvsamson Thanks for sharing!

@riteshnoronha
Copy link
Contributor

@fvsamson #331 this is my initial understanding of the V2.0 guideline. I have created the Compliance Doc, Once we finalize a few points, i can get this implemented.

@viveksahu26
Copy link
Collaborator

viveksahu26 commented Nov 18, 2024

In the Issue:

  • It describe the entire scope of the feature (BSI v2 implementation) and its breakdown into smaller tasks.
  • Checklist of tasks such as:
    • Add command for BSI V2.
    • Update existing SBOM fields (e.g., all which were in bsi:1.1.).
    • Update existing component fields (e.g., all which were in bsi:1.1.).
    • Implement new SBOM fields (e.g., e.g., vuln, signature, bomlinks.).
    • Implement new components fields (e.g., e.g., filename, executable, structured, etc.).
    • Add tests for the new features.
    • Update documentation for BSI v2 compliance.

@viveksahu26
Copy link
Collaborator

Reopening this issue. The PRs addressed a small part of this issue, but 2-3 sub-tasks remain to fully resolve it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants