This objective, and the other similar ‘include‘ objectives, simply state what has to be in your Product Working Practices. You may want to include more, but you cannot be missing any of these and still deliver a secure Product.
- Group or Individual
- Product Team
- Artefact
- Product Working Practices
- Concepts
- Product Dependency Tree Generation
- Document
- Product Dependency Tree Generation
- Risk Type
- Viability
- Event
- The Impact of a Security Incident is increased
- Caused By
- Product Delivery Organisation unable to effectively respond and resolve security incidents
- Leading To
- Loss of customers, financial fraud losses, increased TCO, substantial fines/sanctions from an external regulatory body
-
I-SB-B-1-1
Implementation > Secure Build > Software Dependencies
- Do you have solid knowledge about dependencies you're relying on?