Software Bills of Material are a critical part of securing your code against attacks. But there's more to the story. Full protection for the entire supply chain requires threat, malware, and vulnerability detection and secure code signing, in addition to SBOMs. Software security expert Dave Roche maps the supply chain, and shows where vital protection elements intersect to protect software.