Dependency Scanning
What is Dependency Scanning?
Automated analysis of software dependencies and libraries to identify known vulnerabilities that could affect the security of the application.
Terms that appear alongside dependency scanning
Each of these is named in at least one of the same controls as dependency scanning. The number is how many controls name both.
- vulnerability 4 shared controls
- hardening 4 shared controls
- remediation 4 shared controls
- secure coding 4 shared controls
- zero trust 3 shared controls
- network segmentation 3 shared controls
- application security 3 shared controls
- compliance 3 shared controls
Frameworks that govern dependency scanning
What the standards actually require on dependency scanning
Requirements naming dependency scanning across 6 standards, quoted from the control text.
Applications undergo SAST, DAST, dependency scanning, and penetration testing with remediation tracking.
IS-IV.E.2 · Application Security Testing →UR E27 requires equipment manufacturers to provide Software Bill of Materials (SBOM) and demonstrate secure development. SBOM contents per CISA SBOM Minimum Elements + SPDX or CycloneDX format: component name + version + supplier + license + dependency relatio...
IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity · IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity →ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Security (Sekyuritii セキュリティ) is the fifth of 10 Principles per Japan AI Guidelines for Business + addresses cybersecurity throughout AI lifecycle including adversarial attacks specific to ML + traditional cyber threats to AI infrastructure.
JP-AIG-Security-Adversarial-Attack-Protection-Prompt-Injection-Data-Poisoning-Model-Extraction-AISI-Red-Team · Japan AI Guidelines Security + Adversarial Attack Protection + Prompt Injection + Data Poisoning + Model Extraction + Membership Inference + AISI Red-Team + MLSecOps + Supply Chain Security + Foundation Model Vulnerabilities →Apply NZISM Chapters 10 (Network Security) + 11 (System Hardening) + 12 (Software Security and Application Development) covering: network segmentation with cross-domain solutions where applicable + perimeter defence + intrusion detection/prevention + system ha...
NZISM-5 · Network Security, System Hardening, and Application Security →Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover).
OSFIB13-3 · Cyber Security: Identification, Protection, Detection, Response, Recovery →Questions people ask about dependency scanning
What is Dependency Scanning?
Why is Dependency Scanning important for compliance?
Which compliance frameworks address Dependency Scanning?
Where can I learn more about Dependency Scanning?
See how Dependency Scanning applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.