Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Frameworks
Family
Lens
Sekit CSF · Supply Chain Security
ISO/IEC 27001:2022
Sekit CSF · Supply Chain Security · Process
RCF-0329Software supply chain (SBOM)
Software bills of materials are consistently maintained and reviewed for vulnerable or compromised components
ISO/IEC 27001:2022
Keeping the component inventory current and reviewing it for vulnerable or abandoned dependencies is what makes A.5.21's supply chain visibility hold up as dependencies change.
Keeping the component inventory for each application current and reviewing it for vulnerable dependencies extends A.8.8's exposure tracking into the software supply chain.