Docy Child

APPS-4 Dependency Vulnerability Monitoring

Estimated reading: 2 minutes 516 views

What is this control about?

Dependency vulnerability scanning helps automatically find security vulnerabilities in any third-party software dependencies used while developing and testing your applications. As companies increase their usage of third-party software, it is becoming more and more important to track and monitor any vulnerabilities that may arise from these relationships.

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, because we haven’t personally used them.

Vulnerability Scanning Tools
Gitlab Dependency scanning –
GitHub Dependabot –

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • N/A – no templates recommendation

Control implementation

Install a vulnerability monitoring tool to monitor for third-party dependencies

  • The tool must be configured to run continuously, or on a frequent schedule (schedule is up to each company to determine)
  • The tool must be configured to send a notification or alert when issues are found

Implement a formal and repeatable way to resolve any issues identified. The issues must be resolved timely (timeliness is up to each company to define)

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide screenshots of the tool’s settings screen(s), showing that it is configured to check dependencies across your codebase
  • Provide a remediation ticket or document outlining issues found through the tool, which shows that actions were taken to remediate the issue

Evidence example

From the suggested action above, an example is provided below.

See screenshots provided for APPS-3. These follow the same patterns.

Join the conversation

Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.