# SBOM: from component list to response decision

https://thiago.limaesilvatecnologia.com.br/en/artigos/sbom-operational/

Published: 2026-09-12

Inventory must connect to running software.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: February 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

A dependency list does not tell you where a component is used. Without a link to a deployed version, inventory can be accurate yet unhelpful during an incident.

## Practical application

Editorial proposal: connect component, artifact and environment in a traceable chain. In a hypothetical multiversion product, distinguish development packages from customer-serving software. Assign responsibility for updating that link after release.

## How to verify

Select a test component and ask operations to locate affected environments. Record time and gaps without inventing a universal target. The exercise measures whether inventory can turn a notification into an actionable list.

## Sources

- [OWASP — Dependency Graph SBOM Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Dependency_Graph_SBOM_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
