Integration von CSAF in Dependency-Track (CSAF SBOM Matchingsystem)
Buyer: Bundesamt für Sicherheit in der Informationstechnik
- Published
- 27 June 2024
- Place of performance
- DEA22
- Procedure
- Open procedure
- Lots
- 1
- Notice number
- 00381588-2024
- Reference
- 61b0df4b-d267-4c22-9f91-ff963127afd9
- Official source
- Official source
CPV codes
- 72000000Servicios TI: consultoría, desarrollo de software, Internet y apoyo
Description
Das Tool Dependency-Track des Open Web Application Security Project (OWASP) stellt eine Datenbank für Software Bill of Materials (SBOMs) dar. Ziel des Projektes ist es, Dependency-Track so zu erweitern, dass Security Advisories und Vunerability Exploitability eXchange (VEX) im Format des Common Security Advisory Framework (CSAF) eingelesen und mit den vorhandenen SBOMs abgeglichen werden können und es ein CSAF-standardkonformes CSAF-SBOM-Matching-System ist. Durch den Abgleich der SBOMs auch gegen CSAF-Dateien soll es ermöglicht werden, Aussagen zu erhalten, ob und wie eine in der SBOM enthaltene Komponente von einer Schwachstelle betroffen ist. Dadurch lässt sich das Schwachstellenmanagement bei Herstellern und die Marktüberwachung (teil-)automatisieren.
Award criteria
- Quality — siehe Leistungsbeschreibung
Awards
| Awarded to | Amount | Date |
|---|---|---|
| Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. | — | — |
Official publications
- TED · 00381588-2024 · 27 June 2024
- OJS · 124/2024 · 27 June 2024
Other tenders from Bundesamt für Sicherheit in der Informationstechnik
- Projekt 1034: Technische Umsetzung einer SBOM für KI (SBOM4AI)
- Projekt 680: "Quantensichere (Verwaltungs-)PKI (PQ V-PKI)
- Standardisierung von Prüfkriterien und Prüfmethoden für (cloudbasierte) KI-Systeme 2 [AICRIS 2]
- BA 23178 "Lizenzverlängerung Tenzir"
- P689 - IT-Sicherheit auf dem digitalen Verbrauchermarkt: Fokus Missbrauch von Smarthome im sozialen Nahraum (MissSims)
- Wirkbetrieb SM-PKI
- P637 TP3 - Nationaler Biometric Matching Service 2.0; TP3: Acceptance Tests & Evaluation (NBMS 2.0 TP3)
- P 681 - Zertifizierung für BSI TR-03135
- Projekt 696: Weiterentwicklung TR-Biometrie: Hintergrundersetzung (HGE) im Live-Enrolment (LiveHGE)
- P689 - IT-Sicherheit auf dem digitalen Verbrauchermarkt: Fokus Missbrauch von Smarthome im sozialen Nahraum (MissSims)
Frequently asked questions
- Who is the buyer of this tender?
- The contracting authority is Bundesamt für Sicherheit in der Informationstechnik (European Union).
- How can I bid for public tenders in European Union?
- Bids are submitted through the official procurement portal of European Union. El Vínculo helps you find tenders and analyse their documents; submission always happens at the official source.
Create a free account and receive new tenders from European Union matching your business, every day.