Lsware Joonseok Park Managing Director
The spread of AI coding tools has dramatically accelerated code production, but unverified open source of unknown provenance and AI-generated code snippets are flowing into systems unchecked, opening a new blind spot in supply chain security. OWASP Top 10 2025 newly designated "Software Supply Chain Failures" as a core threat, while the EU Cyber Resilience Act begins vulnerability reporting in September 2026 and Korea signals mandatory public-sector SBOM submission by 2027?turning SBOM from a recommendation into a condition of market entry. Yet responding to the thousands of vulnerabilities an SBOM surfaces is impossible. This session presents strategies for securing trustworthy SBOMs, prioritizing risk through real-world exploit intelligence such as EPSS and CISA KEV, and leveraging VEX (Vulnerability Exploitability eXchange) to filter for vulnerabilities that actually affect the product and to document justified non-remediation?building a "chain of trust" that extends from identification to automated control and policy governance, illustrated with global regulatory trends and field cases from finance and manufacturing.
Korean
English
Chinese
Japanese


