Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Promotion - CertIn

Indian Computer Emergency Response Team ( CertIn ) Its pivotal organization formed by Ministry of Electronics and Information Technology 2004. Effective response to Cyber Incidents. Role Safeguard systems a

Promotion - CertIn
  • Indian Computer Emergency Response Team ( CertIn )
  • Its pivotal organization formed by Ministry of Electronics and Information Technology 2004.
  • Effective response to Cyber Incidents.

Role

  • Safeguard systems and network from:
  1. Cyber threats
  2. Including Malware , Hacking and Data Breaches
  • Its key role is to monitor and analyse cyber threats and Vulnerabilities.
  • Source : Government Agencies , Private Sector Organization , International Partners which helps to identify emerging threats and trends.
  • The advisories and alerts are circulated amoung stakeholders.
  • It also conducts awareness program.
  • Fostering a culture of Cyber Security AWARENESS.
  • Aims to empower individuals and Oraganization to protect themselves against Cyber threats.
  • The Role of CERT-In in ensuring cyber security is becoming more critical day-by-day.

Technical Guidelines on | SBOM | QBOM & CBOM | AIBOM | HBOM |

SBOM

  • Software Bill of Materials
  • A complete inventory of software components used in an application.
  • Includes:
  1. Libraries (open source + proprietary)
  2. Versions
  3. Licenses
  4. Dependencies
  5. Vulnerability mapping

AIBOM

  • AI Bill of Materials.
  • It includes servers, sensors, and GPUs. Also AI models , frameworks ,and development tools.
  • Inventory of all AI‑model components, mandatory for AI systems.
Model name, type, version
Training dataset sources
Algorithms & architecture (LLM, CNN, etc.)
Open‑source AI components
External integrations
Governance approvals (MANDATORY per CERT‑In)

Benefits of AIBOM

Minimum Elements Required

Recommendation & Best Practices

  • The format for generating AIBOM for AI solutions should adhere to established standards, such as Software Package Data eXchange (SPDX) or CycloneDX, ensuring compatibility and uniformity across the industry.

  • The AI developer/integrator organization that supplies AI solutions to government and public sector organizations should develop a Vulnerability Exploitability eXchange (VEX) for AI models after a vulnerability or security issue is discovered.

HBOM

  • Hardware Bill of Materials
  • Inventory of hardware components supporting the application.
Servers
Network devices
Storage systems
Firmware versions
End‑of‑life/End‑of‑support status

CBOM

  • Configuration Bill of Materials
  • Inventory of configuration elements that define how the system is deployed.
Config files
Environment variables
Parameter sets
Network config (ports, protocols, IPs)
Deployment descriptors

QBOM

  • Cloud Bill of Materials
  • QBOM is referenced alongside CBOM in the CERT‑In document.
  • A structured inventory of all cloud components used by an application.
Cloud services (AWS, Azure, GCP, etc.)
Compute resources (VMs, containers)
Storage buckets / databases
Identity & access configurations
External APIs hosted on cloud

Notes

  • Pivotal --> extremely important or central because everything else depends on it.
  • foster --> to help or encourage the development of something (especially feelings or ideas).
πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.