Data Provenance (DPS) TC

 View Only
  • 1.  FYI on relevant work

    Posted 06-05-2025 15:37

    Members may be interested in this LinkedIn post about AI SBOM use cases, some of which include some data provenance issues.Note that the work that created this is an industry team that CISA convenes, but is not a standard, is not CISA itself, and is public domain. So we could, if we wanted, extract any part of the document and 'make it our own' should we want to - and we could change it any way we wanted as well (eg using our spec as metadata about the SBOM as opposed to embedding provenance inside the SBOM).

    I'm not advocating anything. Just pointing out the work and possibilities we may or may not want to pursue as part of our use case work.



    ------------------------------
    Duncan Sparrell
    Chief Cyber Curmudgeion
    sFractal Consulting LLC
    Oakton VA
    703-828-8646
    ------------------------------


  • 2.  RE: FYI on relevant work

    Posted 06-05-2025 15:43

    Thank you for flagging this.

     

    When we were sharing the DPS with the broader community late last year, there was a lot of interest in exploring SBOM-related use cases as part of a future iteration of the DPS. So, I suspect this will resonate with a number of folks.

     

    Kristina