Skip to content
arrow_back
search
ISM-1730 policy ASD Information Security Manual (ISM)

Provide a Software Bill of Materials to Consumers

Ensure software users receive a detailed list of included software components.

record_voice_over

Plain language

A Software Bill of Materials (SBOM) is like a list of ingredients for your software. It tells you what software components and versions are included in any application you use. This is important because knowing what’s inside can help identify potential security risks or legal issues, like if a component has vulnerabilities that need to be fixed, which could otherwise lead to hacks or data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A software bill of materials is produced and made available to consumers of software.
policy ASD Information Security Manual (ISM) ISM-1730
priority_high

Why it matters

Without an SBOM, vulnerabilities in third-party components may be missed, slowing mitigation and increasing breach risk.

settings

Operational notes

Automate SBOM generation in CI/CD and publish it with every release; keep component identifiers/versions consistent across updates.

Mapping detail

Mapping

Direction

Controls