<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CISA on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/tags/cisa/</link><description>Recent content in CISA on OpenChain KWG</description><generator>Hugo</generator><language>ko</language><lastBuildDate>Mon, 10 Aug 2026 11:20:08 +0900</lastBuildDate><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/tags/cisa/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA 2026 SBOM 최소 요소: 데이터 필드 7개에서 17개로, 무엇을 준비할 것인가</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/blog/2026/08/09/cisa-sbom-minimum-elements/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/blog/2026/08/09/cisa-sbom-minimum-elements/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;이 글은 Claude Code를 이용해 작성했고, 인용한 핵심 사실은 1차 출처로 교차 검증했습니다.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="요약"&gt;요약&lt;/h2&gt;
&lt;p&gt;2026년 7월 29일, 미국 사이버보안·인프라보안국(Cybersecurity and Infrastructure Security Agency, CISA)을 비롯한 18개 기관이 소프트웨어 자재 명세서(Software Bill of Materials, SBOM)가 최소한 담아야 할 요소(Minimum Elements) 개정판을 발행했습니다&lt;a id="a2-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/blog/2026/08/09/cisa-sbom-minimum-elements/#a2"&gt;A2&lt;/a&gt;. 2021년 미국 통신정보관리청(National Telecommunications and Information Administration, NTIA)이 만든 기준을 개정한 것이 아니라 대체(replaces)한다고 문서가 직접 밝힙니다.&lt;/p&gt;
&lt;p&gt;요구 수준이 눈에 띄게 올라갔습니다. 데이터 필드가 7개에서 17개로 늘었고 운영 원칙 6개가 함께 규정됐습니다. 신규 요소만 10개입니다.&lt;/p&gt;</description></item></channel></rss>