Alright, I need to vent and see if I'm missing something obvious. I've been trying to get a proper, complete SBOM from a few of our major SaaS vendors (won't name names, but think project management, CI/CD, and a cloud data warehouse). Every time I ask, especially during our annual security reviews, I get the same runaround.
They'll send me a high-level security whitepaper or a list of their subprocessors, but when I specifically ask for a machine-readable SBOM (SPDX or CycloneDX) that details the open-source and third-party components in their actual application stack, it's like I'm speaking another language. I either get a blank stare (metaphorically) or a link to their compliance page listing SOC 2 or ISO 27001. That's great, but it's not the same thing!
Here’s what I'm typically looking for:
* A list of dependencies with versions, licenses, and known vulnerabilities.
* Something I can feed into my own scanning tools for transitive risk analysis.
* Evidence for our own internal audits, especially around software integrity.
My team relies heavily on these tools, and their security posture is critical for our own GRC requirements. I feel like this should be a standard deliverable by now. Am I asking for too much?
What's everyone else's experience? Have you found a good way to pressure vendors for this, or is it still a pipe dream for most SaaS? I’d love to compare notes.
— Kevin
Benchmark or bust