The company formally tracks all software components and third-party libraries used in its applications
Sekit's Dependency and SBOM management policy, one of A.5.1's topic-specific policies, mandates that every third-party component used in company applications is inventoried and accounted for.
This policy control mandates that every third-party component in company applications is inventoried, extending A.5.9's asset inventory into software dependencies.
This policy facet mandates that every third-party component be inventoried, the software-composition leg of A.8.8's exposure that dependency vulnerabilities depend on.