Building resilient medical technology supply chains with a software bill of materials.

Building resilient medical technology supply chains with a software bill of materials.
复制标题

DOI:
10.1038/s41746-021-00403-w
复制
发表时间:
2021-02-23
影响因子:
15.2
通讯作者:
Corman J
Corman J
中科院分区:
医学1区
文献类型:
--
作者:
Carmody S;Coravos A;Fahs G;Hatch A;Medina J;Woods B;Corman J

文献摘要

被引文献

相似文献

医疗保健技术的单个软件组件中的漏洞被利用可能会影响患者护理。在医疗保健技术中包含第三方软件组件的风险可以通过利用软件物料清单 (SBOM) 进行部分管理。 SBOM 类似于食品包装上的成分列表,是所有包含的软件组件的列表。 SBOM 提供了一种透明机制,通过更快地识别和修复漏洞来保护软件产品供应链,从而实现降低攻击可行性的目标。 SBOM 有潜力使医疗技术的所有供应链利益相关者受益,而不会显着增加软件生产成本。提高透明度可以为所有人解锁并实现值得信赖、有弹性且更安全的医疗技术。
An exploited vulnerability in a single software component of healthcare technology can affect patient care. The risk of including third-party software components in healthcare technologies can be managed, in part, by leveraging a software bill of materials (SBOM). Analogous to an ingredients list on food packaging, an SBOM is a list of all included software components. SBOMs provide a transparency mechanism for securing software product supply chains by enabling faster identification and remediation of vulnerabilities, towards the goal of reducing the feasibility of attacks. SBOMs have the potential to benefit all supply chain stakeholders of medical technologies without significantly increasing software production costs. Increasing transparency unlocks and enables trustworthy, resilient, and safer healthcare technologies for all.