DeftTrust

← Controls

IS-11:VM-08-SCA

Software composition analysis tracks third-party components. Component of VM-08; ID assigned by ComplianceHub so the automatable SCA half is tracked separately from the vendor disclosure obligation, which is a contractual term and not something a scanner can observe.

Status
No evidence
Policy cadence
Weekly
Last evidence
Next due
Owner
Security Officer / CTO
TSC
CC7.1
Evidence folder
03_Vulnerability_Management
Automatable
Yes
Policy
IS-11
Policy version
v1.1 (2026-06-03)

Collectors

CollectorRelationshipSamplesWhat it observes
scans.dependencies satisfies weekly Scans application lockfiles for known-vulnerable third-party components

Evidence satisfying this control

CollectedCollectorResultSourceDigest
No artifact satisfies this control.

Definition history

ChangedFieldFromToSource
2026-09-10 03:32 __created__ weekly sync_controls

A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.