Promotion - CertIn
Indian Computer Emergency Response Team ( CertIn ) Its pivotal organization formed by Ministry of Electronics and Information Technology 2004. Effective response to Cyber Incidents. Role Safeguard systems a
- Indian Computer Emergency Response Team ( CertIn )
- Its pivotal organization formed by Ministry of Electronics and Information Technology 2004.
- Effective response to Cyber Incidents.
Role
- Safeguard systems and network from:
- Cyber threats
- Including Malware , Hacking and Data Breaches
- Its key role is to monitor and analyse cyber threats and Vulnerabilities.
- Source : Government Agencies , Private Sector Organization , International Partners which helps to identify emerging threats and trends.
- The advisories and alerts are circulated amoung stakeholders.
- It also conducts awareness program.
- Fostering a culture of Cyber Security AWARENESS.
- Aims to empower individuals and Oraganization to protect themselves against Cyber threats.
- The Role of CERT-In in ensuring cyber security is becoming more critical day-by-day.
Technical Guidelines on | SBOM | QBOM & CBOM | AIBOM | HBOM |
SBOM
- Software Bill of Materials
- A complete inventory of software components used in an application.
- Includes:
- Libraries (open source + proprietary)
- Versions
- Licenses
- Dependencies
- Vulnerability mapping
AIBOM
- AI Bill of Materials.
- It includes servers, sensors, and GPUs. Also AI models , frameworks ,and development tools.
- Inventory of all AIβmodel components, mandatory for AI systems.
Model name, type, version
Training dataset sources
Algorithms & architecture (LLM, CNN, etc.)
Openβsource AI components
External integrations
Governance approvals (MANDATORY per CERTβIn)
Benefits of AIBOM
Minimum Elements Required
Recommendation & Best Practices
The format for generating AIBOM for AI solutions should adhere to established standards, such as Software Package Data eXchange (SPDX) or CycloneDX, ensuring compatibility and uniformity across the industry.
The AI developer/integrator organization that supplies AI solutions to government and public sector organizations should develop a Vulnerability Exploitability eXchange (VEX) for AI models after a vulnerability or security issue is discovered.
HBOM
- Hardware Bill of Materials
- Inventory of hardware components supporting the application.
Servers
Network devices
Storage systems
Firmware versions
Endβofβlife/Endβofβsupport status
CBOM
- Configuration Bill of Materials
- Inventory of configuration elements that define how the system is deployed.
Config files
Environment variables
Parameter sets
Network config (ports, protocols, IPs)
Deployment descriptors
QBOM
- Cloud Bill of Materials
- QBOM is referenced alongside CBOM in the CERTβIn document.
- A structured inventory of all cloud components used by an application.
Cloud services (AWS, Azure, GCP, etc.)
Compute resources (VMs, containers)
Storage buckets / databases
Identity & access configurations
External APIs hosted on cloud
Notes
- Pivotal --> extremely important or central because everything else depends on it.
- foster --> to help or encourage the development of something (especially feelings or ideas).
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.



