Software Component Verification Standard
search
⌘Ctrlk
Software Component Verification Standard
  • Cover
  • Frontispiece
  • Preface
  • Using SCVS
  • Assessment and Certification
  • V1 Inventory
  • V2 Software Bill of Materials
  • V3 Build Environment
  • V4 Package Management
  • V5 Component Analysis
  • V6 Pedigree and Provenance
  • Guidance: Open Source Policy
  • Appendix A: Glossary
  • Appendix B: References
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

Appendix B: References

The following resources may be useful to users and adopters of this standard:

hashtag
OWASP Projects

  • OWASP Packmanarrow-up-right

  • OWASP Software Assurance Maturity Model (SAMM)arrow-up-right

hashtag
Community Projects

  • Open Source Security Foundation - Threats, Risks, and Mitigations in the Open Source Ecosystemarrow-up-right

hashtag
Others

  • InnerSourcearrow-up-right

  • Cybersecurity Maturity Model Certification (CMMC)arrow-up-right

  • NIST 800-53 Security and Privacy Controls for Federal Information Systems and Organizationsarrow-up-right

  • NIST 800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizationsarrow-up-right

  • NIST 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizationsarrow-up-right

  • NTIA Documents on Software Bill of Materialsarrow-up-right

  • Model Procurement Contract Language Addressing Cybersecurity Supply Chain Riskarrow-up-right

  • Guide on Cybersecurity Procurement Language in Task Order Requests for Proposals for Federal Facilitiesarrow-up-right

  • Energy Sector Control Systems Working Group (ESCSWG)arrow-up-right

hashtag
SBOM Formats

  • CycloneDXarrow-up-right

  • SPDXarrow-up-right

  • SPDX XMLarrow-up-right

  • ISO/IEC 19770-2:2015 (SWID)arrow-up-right

PreviousAppendix A: Glossarychevron-left

Last updated 5 years ago

  • OWASP Projects
  • Community Projects
  • Others
  • SBOM Formats