[Photo: Sparrow]

[Digital Today reporter Chi-gyu Hwang] Application security company Sparrow on Wednesday morning held the Application Security Summit 2026 and shared strategies to respond to software supply chain attacks and ways to manage supply chain threats using software bills of materials (SBOM).

Held at Fairmont Ambassador Seoul in Yeouido under the theme, "Software supply chain security 강화 roadmap: beyond response to strategy," the event drew about 30 leaders from a range of industries including finance, manufacturing and retail.

In a keynote speech, Sparrow CEO Il-soo Jang (장일수) explained regulatory trends on software supply chain security in major countries and underscored the importance of SBOM. Jang said, "As the level of SBOM requirements continues to rise in major countries such as the United States, the EU and Japan, it is important to secure SBOM accuracy and reliability and build a foundation to systematically manage it from creation to verification and distribution." As concrete execution strategies, he presented SBOM lifecycle management, establishing an SBOM-based vulnerability response system, and secure distribution through digital signatures and verification.

Goo-yong Yeo (여구용), Sparrow's head of business, introduced ways to respond to the government's software supply chain security 강화 roadmap. Emphasising security built into the entire software development lifecycle, Yeo shared customer cases in which they built a system to continuously manage open-source component use and vulnerabilities by using Sparrow Enterprise, an integrated application security testing platform. He also suggested a way to secure visibility across the supply chain by identifying supply chain relationships between suppliers and buyers based on SBOM sharing history.

In the final presentation, Sparrow CTO Jong-won Yoon (윤종원) stressed the importance of blocking the introduction of vulnerable components in advance and setting remediation priorities for discovered vulnerabilities based on actual risk and impact. Yoon said, "To do this, Sparrow applies component intake control policies from the open-source intake stage to prevent the use of vulnerable components in advance, and provides a function that uses AI to suggest remediation priorities by considering asset criticality and vulnerability risk."

Keyword

#Sparrow #Application Security Summit 2026 #SBOM #Sparrow Enterprise #Fairmont Ambassador Seoul
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.