Files
mehl.mx/content/blog/2023-06-upstream-hardware-bom-fireside/index.md
2026-02-23 15:49:41 +01:00

22 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Hardware Bills of Material with Deutsche Bahn"
date: 2023-06-07
categories:
- english
- presentation
tags:
- SupplyChain
- Security
- DeutscheBahn
video: https://www.youtube.com/watch?v=59WQeWXFmNw
event:
name: Upstream 2023
href: https://upstream.live/
---
At Upstream 2023, I participated in a fireside chat with Luis Villa (Tidelift) and my colleague Erik Schaufuss exploring the fascinating intersection between Software Bills of Materials (SBOMs) and Hardware Bills of Materials (HBOMs) within Deutsche Bahn's complex supply chain. As Germany's national railway company with hundreds of federated subsidiaries, we face unique challenges in managing both rolling stock hardware and the increasingly software-driven assets within trains. The discussion centered on how learnings from the software supply chain transparency movement particularly around standards like CycloneDX can inform and improve hardware supply chain management.
The conversation explored Deutsche Bahn's federated corporate structure and how this complexity makes supply chain management particularly challenging yet critical. We discussed the need for standards to communicate information across organizational boundaries, the clash between traditional hardware procurement and modern software practices, and how tracking components in both domains presents parallel challenges. The fireside chat highlighted practical experiences in bridging the gap between software and hardware supply chain transparency, and the importance of ISO standards and industry collaboration in this evolving space.
This session demonstrated that whether dealing with software packages or physical train components, the fundamental challenges of transparency, traceability, and security have more in common than one might initially expect.