
Recklesss Compliance
A Federal Security & Compliance career is a very rewarding career - we get the honor and privilege of protecting some of the most guarded assets of our great country. However, it doesn’t come without a cost. We often take the brunt of the beating when it comes to the regulations that are impeding innovation.
Join federal security professional Max Aulakh as he distills the challenges facing our career field, pulling back the curtain on culture, emerging technical knowledge, ATOs, CMMC and various federal cyber frameworks.
Each episode is jam-packed with powerful information to cut through the noise. We will break down tools, tips and techniques to help you get better and to quickly get through the federal accreditation processes. It doesn’t matter what type of systems or technology you are dealing with, if you have heard of or are familiar with terms like STIGS, SAP, SAR, FedRAMP, and ConMON or newer terms like cATO, Big Bang, OSCAL, CMMC and SBOMs - we will break it all down.
Recklesss Compliance
Unpacking SBOMs: Software Supply Chain Risks & Compliance Challenges
Welcome to this episode of the Reckless Compliance podcast, brought to you by Ignyte, where we share our expertise on cyber risk and help you navigate the complexities of federal compliance. I am your host, Max Aulakh.
Our guest today is Aaron Bray, co-founder of Phylum, a company specializing in securing software supply chains.
We discuss:
- What is an SBOM? Understanding the Software Bill of Materials and its role in risk management
- Open-source security risks: How third-party libraries expose organizations to vulnerabilities
- Executive Orders & Compliance: The evolving enforcement of SBOMs in federal regulations
- Automation & AI in SBOM Management: How organizations can use automation to stay compliant and secure
- Challenges of Software Supply Chains: Managing risks with thousands of dependencies and contributors
Max Aulakh Bio:
Max is the CEO of Ignyte Assurance Platform and a Data Security and Compliance leader delivering DoD-tested security strategies and compliance that safeguard mission-critical IT operations. He has trained and excelled while working for the United States Air Force. He maintained and tested the InfoSec and ComSec functions of network hardware, software, and IT infrastructure for global unclassified and classified networks.
Max Aulakh on LinkedIn
Ignyte Assurance Platform Website