Establish and manage an updated inventory of third-party components used in development, often
referred to as a “bill of materials,” as well as components slated for future use. This inventory is to
include any risks that each third-party component could pose. Evaluate the list at least monthly
to identify any changes or updates to these components, and validate that the component is still
supported.
The organization creates a centralized bill of materials (BOM) repository to manage third-party components, including detailed information, tracking, regular updates, risk assessments, vulnerability monitoring, and facilitate communication with development teams for proactive security management.