<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Sun, 10 May 2026 07:53:20 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Tech Transforms - Episodes Tagged with “Sbom”</title>
    <link>https://techtransforms.fireside.fm/tags/sbom</link>
    <pubDate>Tue, 09 Sep 2025 10:30:00 -0400</pubDate>
    <description>Global technology is changing the way we live. Critical government decisions affect the intersection of technology advancement and human needs. This podcast talks to some of the most prominent influencers shaping the landscape to understand how they are leveraging technology to solve complex challenges while also meeting the needs of today's modern world.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Tech Transforms, brought to you by Owl Cyber Defense, talks to some of the most prominent influencers shaping government technology.</itunes:subtitle>
    <itunes:author>Carolyn Ford</itunes:author>
    <itunes:summary>Global technology is changing the way we live. Critical government decisions affect the intersection of technology advancement and human needs. This podcast talks to some of the most prominent influencers shaping the landscape to understand how they are leveraging technology to solve complex challenges while also meeting the needs of today's modern world.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/8/81d9d6b0-0045-48da-8495-fd87c4613d7f/cover.jpg?v=3"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Carolyn Ford</itunes:name>
      <itunes:email>Galadrielford@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="Government"/>
<item>
  <title>Episode 105: From Compliance to Capability: Securing the Federal Software Supply Chain in the Age of AI</title>
  <link>https://techtransforms.fireside.fm/105</link>
  <guid isPermaLink="false">b78757c1-8167-4e0d-8921-afe3fa00ca3b</guid>
  <pubDate>Tue, 09 Sep 2025 10:30:00 -0400</pubDate>
  <author>Carolyn Ford</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/81d9d6b0-0045-48da-8495-fd87c4613d7f/b78757c1-8167-4e0d-8921-afe3fa00ca3b.mp3" length="49888610" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Carolyn Ford</itunes:author>
  <itunes:subtitle>On this episode of Tech Transforms, host Carolyn Ford welcomes Antoine Harden, Regional VP of Federal at Sonatype, to unpack one of the most urgent challenges in federal cybersecurity.</itunes:subtitle>
  <itunes:duration>40:57</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/8/81d9d6b0-0045-48da-8495-fd87c4613d7f/episodes/b/b78757c1-8167-4e0d-8921-afe3fa00ca3b/cover.jpg?v=1"/>
  <description>&lt;p&gt;On this episode of Tech Transforms, host Carolyn Ford welcomes Antoine Harden, Regional VP of Federal at Sonatype, to unpack one of the most urgent challenges in federal cybersecurity: securing the software supply chain. With more than 25 years of experience at Oracle, Google, and now Sonatype, Antoine shares why software supply chain risks from SolarWinds to Log4j have pushed SBOMs (Software Bills of Materials) and continuous monitoring into the spotlight.&lt;/p&gt;

&lt;p&gt;Together, they break down what SBOMs are (think nutrition labels for software), how mandates like Executive Order 14028 and frameworks like NIST’s Secure Software Development Framework (SSDF) and DoD’s SWFT are changing the compliance landscape, and why automation is essential to get from static ATOs to continuous authorization.&lt;/p&gt;

&lt;p&gt;Antoine also explains how Sonatype uses AI and software composition analysis tools to close critical gaps in open source and AI-heavy environments, helping agencies shift left, reduce vulnerabilities, and accelerate secure delivery of mission-critical systems. Along the way, the conversation covers everything from JFK delays caused by vulnerabilities, to the risks of “ludicrous speed” AI adoption, to the surprising history of Project Pigeon in WWII.&lt;/p&gt;

&lt;p&gt;For federal leaders ready to take action, Antoine offers one concrete step: start with a single mission-critical application, mandate an SBOM, and see what hidden risks you uncover.&lt;/p&gt;

&lt;p&gt;Show Notes:&lt;br&gt;
Connect with Antoine  &lt;a href="https://www.linkedin.com/in/antoine-harden-mba-035a441/" target="_blank" rel="nofollow noopener"&gt;https://www.linkedin.com/in/antoine-harden-mba-035a441/&lt;/a&gt; &lt;br&gt;
&lt;a href="https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity" target="_blank" rel="nofollow noopener"&gt;Executive Order 14028&lt;/a&gt;&lt;a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-218.pdf" target="_blank" rel="nofollow noopener"&gt;NIST Secure Software Development Framework (SSDF)&lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.cisa.gov/zero-trust-maturity-model" target="_blank" rel="nofollow noopener"&gt;CISA Zero Trust Maturity Model&lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.defense.gov/News/Releases/Release/Article/4174350/software-fast-track-initiative/" target="_blank" rel="nofollow noopener"&gt;DoD’s SWFT (Software Fast Track Initiative) &lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.sonatype.com/resources?_gl=1*1jtfn7r*_up*MQ..*_ga*Mzc1ODU4NTM3LjE3NTYzMTc3NTc.*_ga_3W70E95Z6Q*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_2TMM6KZPXQ*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_08HT33J01V*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw" target="_blank" rel="nofollow noopener"&gt;Sonatype Resource Center&lt;/a&gt; &lt;/p&gt;
</description>
  <itunes:keywords>SBOM, Software Supply Chain, Compliance, AI</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>On this episode of Tech Transforms, host Carolyn Ford welcomes Antoine Harden, Regional VP of Federal at Sonatype, to unpack one of the most urgent challenges in federal cybersecurity: securing the software supply chain. With more than 25 years of experience at Oracle, Google, and now Sonatype, Antoine shares why software supply chain risks from SolarWinds to Log4j have pushed SBOMs (Software Bills of Materials) and continuous monitoring into the spotlight.</p>

<p>Together, they break down what SBOMs are (think nutrition labels for software), how mandates like Executive Order 14028 and frameworks like NIST’s Secure Software Development Framework (SSDF) and DoD’s SWFT are changing the compliance landscape, and why automation is essential to get from static ATOs to continuous authorization.</p>

<p>Antoine also explains how Sonatype uses AI and software composition analysis tools to close critical gaps in open source and AI-heavy environments, helping agencies shift left, reduce vulnerabilities, and accelerate secure delivery of mission-critical systems. Along the way, the conversation covers everything from JFK delays caused by vulnerabilities, to the risks of “ludicrous speed” AI adoption, to the surprising history of Project Pigeon in WWII.</p>

<p>For federal leaders ready to take action, Antoine offers one concrete step: start with a single mission-critical application, mandate an SBOM, and see what hidden risks you uncover.</p>

<p>Show Notes:<br>
Connect with Antoine  <a href="https://www.linkedin.com/in/antoine-harden-mba-035a441/" rel="nofollow">https://www.linkedin.com/in/antoine-harden-mba-035a441/</a> <br>
<a href="https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity" rel="nofollow">Executive Order 14028</a><a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-218.pdf" rel="nofollow">NIST Secure Software Development Framework (SSDF)</a><br>
<a href="https://www.cisa.gov/zero-trust-maturity-model" rel="nofollow">CISA Zero Trust Maturity Model</a><br>
<a href="https://www.defense.gov/News/Releases/Release/Article/4174350/software-fast-track-initiative/" rel="nofollow">DoD’s SWFT (Software Fast Track Initiative) </a><br>
<a href="https://www.sonatype.com/resources?_gl=1*1jtfn7r*_up*MQ..*_ga*Mzc1ODU4NTM3LjE3NTYzMTc3NTc.*_ga_3W70E95Z6Q*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_2TMM6KZPXQ*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_08HT33J01V*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw" rel="nofollow">Sonatype Resource Center</a></p>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>On this episode of Tech Transforms, host Carolyn Ford welcomes Antoine Harden, Regional VP of Federal at Sonatype, to unpack one of the most urgent challenges in federal cybersecurity: securing the software supply chain. With more than 25 years of experience at Oracle, Google, and now Sonatype, Antoine shares why software supply chain risks from SolarWinds to Log4j have pushed SBOMs (Software Bills of Materials) and continuous monitoring into the spotlight.</p>

<p>Together, they break down what SBOMs are (think nutrition labels for software), how mandates like Executive Order 14028 and frameworks like NIST’s Secure Software Development Framework (SSDF) and DoD’s SWFT are changing the compliance landscape, and why automation is essential to get from static ATOs to continuous authorization.</p>

<p>Antoine also explains how Sonatype uses AI and software composition analysis tools to close critical gaps in open source and AI-heavy environments, helping agencies shift left, reduce vulnerabilities, and accelerate secure delivery of mission-critical systems. Along the way, the conversation covers everything from JFK delays caused by vulnerabilities, to the risks of “ludicrous speed” AI adoption, to the surprising history of Project Pigeon in WWII.</p>

<p>For federal leaders ready to take action, Antoine offers one concrete step: start with a single mission-critical application, mandate an SBOM, and see what hidden risks you uncover.</p>

<p>Show Notes:<br>
Connect with Antoine  <a href="https://www.linkedin.com/in/antoine-harden-mba-035a441/" rel="nofollow">https://www.linkedin.com/in/antoine-harden-mba-035a441/</a> <br>
<a href="https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity" rel="nofollow">Executive Order 14028</a><a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-218.pdf" rel="nofollow">NIST Secure Software Development Framework (SSDF)</a><br>
<a href="https://www.cisa.gov/zero-trust-maturity-model" rel="nofollow">CISA Zero Trust Maturity Model</a><br>
<a href="https://www.defense.gov/News/Releases/Release/Article/4174350/software-fast-track-initiative/" rel="nofollow">DoD’s SWFT (Software Fast Track Initiative) </a><br>
<a href="https://www.sonatype.com/resources?_gl=1*1jtfn7r*_up*MQ..*_ga*Mzc1ODU4NTM3LjE3NTYzMTc3NTc.*_ga_3W70E95Z6Q*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_2TMM6KZPXQ*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw*_ga_08HT33J01V*czE3NTYzMTc3NTUkbzEkZzAkdDE3NTYzMTc3NTUkajYwJGwwJGgw" rel="nofollow">Sonatype Resource Center</a></p>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
