Fortress Results

2-June-2022 DC CAW

Fortress Results

What Contributed

recap sweat equity here, can ref to sweat page

Fortress Information Security was able to demo a few capabilities of our PACE system, using our File Integrity Assurance (FIA) tool, including:

  1. Collect SBOM with Command using FIA as a Posture Collection Service (PCS) to use an API to upload an SBOM
  2. Retrieve SBOMs using FIA as a Posture Attribute Repository (PAR) to retrieve an uploaded SBOM, then
  3. Evaluate the SBOM’s data using FIA as a Posture Evaluation Service (PES) and initiate an SBOM Analysis job, and retrieve an Analysis Report

    • We also demonstrated the functionality and output of a Fortress SBOM Analysis Report.

In addition, we learned about how other workshop attendees are using OpenC2 and STIX/TAXII feeds to facilitate sharing of threat information. On the fly, we wrote a custom integration to:

  1. Upload an SBOM to a STIX/TAXII Feed (Likely an industry first)
  2. Initiate a Fortress SBOM Analysis job when a new SBOM is detected
  3. Publish the Analysis Report to the STIX/TAXII Feed
  4. And finally, we demonstrated the SBOM Blockchain solution to share upload and share SBOM and other software supply supply chain attestations. Other attendees complimented the appearance and functionality of the blockchain system.

Use Cases

Anchore

IBM

Take aways

We need to understand and actively support integrations with existing and emerging standards, including OpenC2, PACE, CSAF, and STIX/TAXII.

Jump to

Return to Contributing Companies/Agencies/Universities

return to Contributing Companies/Agencies/Universities

Return to Results

return to Results

Return to Agenda

return to Agenda

Return to Home

return to Home