Skip to content

Dependency Scanning

What is Dependency Scanning?

Automated analysis of software dependencies and libraries to identify known vulnerabilities that could affect the security of the application.

Information Security

Each of these is named in at least one of the same controls as dependency scanning. The number is how many controls name both.

What the standards actually require on dependency scanning

Requirements naming dependency scanning across 6 standards, quoted from the control text.

Applications undergo SAST, DAST, dependency scanning, and penetration testing with remediation tracking.

IS-IV.E.2 · Application Security Testing

UR E27 requires equipment manufacturers to provide Software Bill of Materials (SBOM) and demonstrate secure development. SBOM contents per CISA SBOM Minimum Elements + SPDX or CycloneDX format: component name + version + supplier + license + dependency relatio...

IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity · IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity
ISMAP (Japan)1 control

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

Security (Sekyuritii セキュリティ) is the fifth of 10 Principles per Japan AI Guidelines for Business + addresses cybersecurity throughout AI lifecycle including adversarial attacks specific to ML + traditional cyber threats to AI infrastructure.

JP-AIG-Security-Adversarial-Attack-Protection-Prompt-Injection-Data-Poisoning-Model-Extraction-AISI-Red-Team · Japan AI Guidelines Security + Adversarial Attack Protection + Prompt Injection + Data Poisoning + Model Extraction + Membership Inference + AISI Red-Team + MLSecOps + Supply Chain Security + Foundation Model Vulnerabilities

Apply NZISM Chapters 10 (Network Security) + 11 (System Hardening) + 12 (Software Security and Application Development) covering: network segmentation with cross-domain solutions where applicable + perimeter defence + intrusion detection/prevention + system ha...

NZISM-5 · Network Security, System Hardening, and Application Security
OSFI B-131 control

Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover).

OSFIB13-3 · Cyber Security: Identification, Protection, Detection, Response, Recovery

Questions people ask about dependency scanning

What is Dependency Scanning?
Automated analysis of software dependencies and libraries to identify known vulnerabilities that could affect the security of the application.
Why is Dependency Scanning important for compliance?
Dependency Scanning is a key concept in Information Security. Understanding dependency scanning helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Dependency Scanning?
Dependency Scanning appears in the requirement text of FFIEC IT Examination Handbook, IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, ISMAP (Japan), Japan AI Guidelines, New Zealand Information Security Manual (NZISM). Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Dependency Scanning?
Explore our compliance framework pages to see how dependency scanning applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Dependency Scanning applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.