CIO Brief: Software Bills of Materials After Log4Shell
Retrospective: this article looks back at events from December 2021, written in 2026 with the benefit of hindsight.
The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just figuring out where they were affected. A "software bill of materials" — an ingredient list for software — would have answered that in hours.
What an SBOM is
A software bill of materials lists the components and libraries inside an application, like an ingredient label. When a vulnerability is found in a component, you can search your SBOMs and immediately know which applications contain it.
The business impact of not having one
- Slow response to critical vulnerabilities.
- Uncertainty when customers ask, "Are you affected?"
- Wasted effort checking systems manually.
Why it's becoming expected
US federal policy after 2021 pushed software suppliers toward SBOMs, and many large customers now request them in procurement. Regulators in the EU are moving in a similar direction for products with digital components.
Questions to ask your team
- If a major vulnerability were announced today in a common library, how long would it take to know which of our systems contain it?
- Do we generate SBOMs for software we build?
- Do we ask vendors for SBOMs?
What good looks like
SBOMs generated automatically for internal applications, requested from key vendors, and stored in a searchable inventory linked to vulnerability scanning.
The decision
Ask your development teams to generate SBOMs as part of every build. It's a small change in the pipeline with large value on the day the next Log4Shell arrives.
- Log4Shell (Dec 2021): The Vulnerability in Everything Incident Teardowns
- How to Find Vulnerable Libraries in Azure and AWS Workloads How-To & Hardening
- Detecting Log4j Exploitation: Sentinel and GuardDuty Detections Detection & Response