What is a Cryptographic Bill of Materials (CBOM)?
A CBOM is a structured record of cryptographic components and their context within a defined scope. Vista generates scoped CycloneDX CBOM artifacts from inventory evidence, with provenance, freshness information, and a content hash.
How is a CBOM different from an SBOM?
An SBOM describes software components and dependencies. A CBOM focuses on cryptographic components, such as algorithms, certificates, and related properties. They answer complementary questions: software composition and cryptographic use.
What makes a CBOM clean and useful?
A useful CBOM has an explicit scope, consistent identities, traceable observations, and visible unresolved findings. Cleaning the inventory means correcting records and investigating findings, not removing inconvenient evidence or claiming that an export proves compliance.
Does a CBOM prove that we are compliant?
A CBOM is a record of cryptographic inventory at a point in time. Enterprise attestation adds the evaluated control results. Neither is a certification or a substitute for the wider technical, operational, and organizational evidence an audit may require.
Do we need to resolve every finding before generating a CBOM?
No. You can generate a baseline while issues remain. Use it to establish the current state, organize remediation, and generate later artifacts to document progress. A missing attestation layer must not be interpreted as a passing result.
Are CBOMs generated automatically on a schedule?
Generation is on demand through the UI or API. Continuous inventory evaluation and CBOM generation are separate operations; Vista does not currently schedule recurring CBOM artifacts.
Can our own policies apply to the inventory?
Enterprise users can author custom policies with controls and typed measurements against inventory. Governed threshold overrides are also Enterprise; override authoring is provisioned through the API rather than a tenant self-service screen.
Can recipients verify a downloaded PDF’s signature?
Integrity verification applies to the canonical CycloneDX artifact. PDF and SPDX files are convenient projections. Enterprise HMAC signatures require access to the shared secret or the verification endpoint.