Software Composition Analysis
What is Software Composition Analysis?
Tools and processes that identify open-source components in software and detect known vulnerabilities, licensing issues, and outdated dependencies.
Terms that appear alongside software composition analysis
Each of these is named in at least one of the same controls as software composition analysis. The number is how many controls name both.
- security testing 4 shared controls
- owasp 3 shared controls
- application security testing 3 shared controls
- application security 3 shared controls
- devsecops 2 shared controls
- software bill of materials 2 shared controls
- secure coding 2 shared controls
- supply chain security 2 shared controls
Frameworks that govern software composition analysis
What the standards actually require on software composition analysis
Requirements naming software composition analysis across 6 standards, quoted from the control text.
All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported in...
ISM-2028 · All software artefacts are tested to detect known weaknesses using static application secu →Maintain inventory of open source and third party components in code using Software Composition Analysis tools.
DS-2 · Ensure software supply chain security →Security Layer 3 Applications per X.805 Clause 7.3: The Applications Security Layer addresses requirements of network-based applications accessed by service provider customers.
X805-Layer3-Applications-Security-Email-Web-Directory-File-Transfer-E-Commerce-Video · ITU-T X.805 Security Layer 3 - Applications Security + Email + Web + Directory + File Transfer + E-Commerce + Video Conferencing + IM + Office Collaboration + SaaS + B2B EDI + Mobile Apps + APIs →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...
KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC →Implement IT Project Management + Software Development Lifecycle + IT Service Management per MAS TRM Chapters 4 + 5 + 6. Chapter 4 IT Project Management - project initiation approval + business case + risk assessment + technology security review + steering com...
MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL · MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL →Questions people ask about software composition analysis
What is Software Composition Analysis?
Why is Software Composition Analysis important for compliance?
Which compliance frameworks address Software Composition Analysis?
Where can I learn more about Software Composition Analysis?
See how Software Composition Analysis applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.