ossf/sbom-everywhere

Please add an Analyze "Bubble"

rjb4standards opened this issue · 0 comments

There are several products that analyze SBOMs for various purposes. BCG's Software Assurance Guardian Point Man (SAG-PM) performs a comprehensive CSCRM software product risk assessment resulting in a trust score which is placed into a publicly accessible "Trust Registry" following IETF SCITT concepts.

Please list BCG's SAG-PM as a commercial product with implementing Analyze functions for Risk Assessments.