Annex 12.4.1
Mapped SPARTA techniques (6)
Techniques referencing this article
Asset-inventory obligations require maintenance of accurate, up-to-date software-component inventories; without them the entity cannot match known vulnerabilities to its installed COTS/FOSS surface.
Asset inventories at component granularity (lot, serial, configuration state) are the data on which lifecycle traceability and tamper-detection workflows depend; without that inventory the entity cannot reason about what was modified pre-delivery.
Asset-inventory obligations at component granularity (lot, configuration, test history) underpin the lifecycle traceability needed to detect hardware-backdoor classes at delivery and during operations.
Inventories of communications equipment (antennas, transponders, modems, receivers) are exactly the asset-inventory content the implementing regulation requires the entity to maintain; the inventory's confidentiality classification determines whether equipment recon can succeed against the entity.
Asset inventories at component granularity contain exactly the lot, serial and configuration data hardware reconnaissance targets; inventory protection determines whether that data is reachable.
Software-asset inventories carry the version, dependency and provenance data the recon enumerates; their classification controls determine whether the data is exfiltrable through normal access paths.