Capability Build & Validation: SBOM & Dependency Security

Software component inventory and dependency vulnerability monitoring

 
01

Definition of visibility into software composition and dependencies

  • Applications, services, and build artifacts in scope
  • Open-source and third-party components across environments
  • Dependency sources (repositories, registries, package managers)
  • Ownership and responsibility for component risk
 
02

Establishment of continuous component inventory and monitoring

  • Generation and management of SBOMs across build and runtime artifacts
  • Integration of dependency scanning into CI/CD pipelines
  • Vulnerability intelligence mapping (e.g., CVEs, advisories) to components
  • Policy definition for allowed and blocked components and versions
  • Reporting of component inventory and risk exposure
 
03

Verification that dependency risks are accurately identified and actionable

  • Testing SBOM completeness and coverage across artifacts
  • Validation of vulnerability detection against known issues
  • Review of prioritization based on exploitability and exposure
  • Identification of gaps in dependency tracking (transitive dependencies, shadow components)
  • Continuous tuning of policies and monitoring processes
 
04

Supports alignment with

  • NIST SSDF (secure software supply chain practices)
  • ISO/IEC 27001 (asset management and secure development controls)
  • NIST SP 800-218 / 800-161 (software supply chain security)
  • CIS Controls (inventory and vulnerability management)
  • DORA and NIS2 regulatory expectations for software supply chain risk management