Skip to content

Add audit schema extension #35

@stevespringett

Description

@stevespringett

The ability to optionally supplement the BOM with results of human analysis and opinion is required for moderate to high assurance use cases.

Examples include:

  • Analysis of the accuracy of each components data as well as the accuracy of the BOM in its entirety.
  • Analysis of the completeness of each components data as well as the completeness of the BOM in its entirety.
  • Analysis and determination of the completeness and accuracy of each components inclusions, dependencies, provenance and pedigree. Assertions, known unknowns, etc.
  • Analysis of the tools and methods used to create the BOM.

Each analysis should attribute decisions to the people, processes, or machines that made them, timestamps, and signatures, forming an audit trail.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions