Implement software supply chain risk management
Establish a repeatable process to identify, assess, treat, monitor, and communicate risks arising from software components, suppliers, services, build systems, and distribution channels.
Example: Establish a repeatable process to identify, assess, treat, monitor, and communicate risks across components, suppliers, services, build systems, and distribution channels.
Counterexample: Prioritize from severity alone while omitting reachability, exposure, privilege, support, and business impact, and the available records do not support component risk. | Regard an earlier not-reachable or no-known-issue result as permanent assurance, and the bounded finding on supply chain risk governance is treated as permanent. | Let a scanner or technical owner accept residual exposure without an authorized business owner, and supply chain risk governance lacks an authorized risk owner.
Limitations: The supplier-risk process covers direct components but omits build services, distribution channels, and external service dependencies.
Tradeoffs: Establish a repeatable process to identify, assess, treat, monitor, and communicate risks across components, suppliers, services, build systems, and distribution channels.