CYB-201Cybersecurity & Threat

Software Supply Chain: SBOMs, VEX and Component Monitoring in Practice

Customers and regulators are starting to ask for SBOMs. Generate them, ingest your vendors', and use VEX to know what's really exposed.

6 lessons About 3 hours 3 ALCs Certificate on completion

Prepares you for: CCSP · SecurityX · AWS Certified Security – Specialty

What you'll be able to do

  • Generate SBOMs for your products and ingest them from vendors
  • Match components to CVEs and track when an SBOM goes stale
  • Use VEX to say which vulnerabilities don't affect you, and prove it
  • Ask vendors for SBOMs in terms they can actually meet
You finish with

A working SBOM program

What's in it. Generation, ingestion, CVE matching, VEX handling, staleness rules and vendor SBOM requests.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Application security, product security and supply chain risk teams.

What's inside

  1. Part 1Where the requirement comes from 18 min
  2. Part 2How small teams and enterprises meet it 17 min
  3. Part 3The method, step by step 20 min
  4. Part 4Hands-on lab: small team choose one 90 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 16 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageGenerate your own SBOM and answer customers.
EnterpriseIngest vendor SBOMs at scale and route CVEs to remediation.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a working SBOM program?6 lessons, about 3 hours. Start whenever you're ready.
Join and enroll