Transparency, Security, and Compliance: Innovative Governance of SBOM, CBOM, and AIBOM in Cathay's Microservices Supply Chain

Time
2025年8月09日 15:10 ~ 15:40
Speaker
趙振勝 (Sky)
Room
TR513
Collaborative Notes
https://hackmd.io/Hkqga9Zdgg
MandarinIntermediate
Open Source Policy

Abstract

As the financial industry accelerates digital transformation, microservices architecture has become essential for achieving agility, scalability, and operational efficiency. At Cathay, the IPE (中台) microservices extensively, yet faces growing challenges in managing software vulnerabilities, cryptographic security, and AI model governance.

This session will introduce Cathay’s strategic adoption of SBOM (Software Bill of Materials), CBOM (Cryptographic Bill of Materials), and AIBOM (AI Bill of Materials) as foundational tools for securing the microservices supply chain:

SBOM: Enhances visibility into third-party and open-source components for proactive vulnerability management.

CBOM: Catalogs cryptographic assets to address post-quantum threats and regulatory requirements.

AIBOM: Tracks AI model metadata for responsible AI governance and risk assessment.

Through real-world practices, this session will demonstrate how Cathay transforms these concepts into practical governance frameworks—strengthening security, ensuring compliance, and maintaining trust in a fast-evolving fintech landscape.

About the Speaker

趙振勝 (Sky)

趙振勝 (Sky)

我是現任國泰金控開源創新發展小組的 DevOps 工程師,擁有 9 年金融業經驗。目前負責雲原生微服務架構下,挑戰將 CNCF 開源項目、資安工具導入金融機構,並其引進成為規範及準則。歡迎一同交流以及學習! Hi! I’m a DevOps engineer at Cathay Financial Holdings, part of the Open Source Innovation Development Team. With 9 years of experience in the financial industry, I’m currently working on bringing CNCF open source projects and security tools into our cloud-native microservices architecture—and helping turn them into practical standards within the organization. I’m always excited to exchange ideas and learn from others in the community. Let’s connect and grow together!