3.4.4—3.4.4
>Control Description
Components use approved and validated code/binaries via the Software Bill of Materials (SBOM) process to ensure that applications that can and cannot support the approach are identified. Applications which can support modern Software-Based Configuration and Management (SBCM) approaches are identified and transitioned. Applications that support SBCM have been transitioned to a production/live environment and are in normal operations. Applications which cannot SBCM are identified and allowed through exception using a risk-based approach.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.