K07 · evidence-bundled critical-infrastructure assurance

Software Bill of Materials

Direct answer

Software Bill of Materials provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Artifact class

Supply-chain record
Stable IDSCA-K07-001
Artifact typeSBOM

Required fields

  • supplier
  • component name
  • version
  • unique identifier
  • dependency relationship
  • author or generator
  • timestamp
  • format and schema version

Validation expectations

  • schema parse
  • unique component identity
  • dependency closure where available
  • artifact hash
  • creation-tool identity
  • update cadence

Limitations

  • does not prove absence of vulnerability
  • does not prove installed state
  • does not prove authenticity unless separately signed and verified

Source relationships

Assurance boundary

Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.