Control Specification
SBOM generation and storage baseline
Supply Chain Security Scanning
SBOM generation and storage baseline defines an enforceable control requirement inside Supply Chain Security Scanning, with measurable checkpoints and operational constraints.
Purpose
Enforce policy and runtime constraints tied to Supply Chain Security Scanning so drift and non-compliant operations are blocked early.
Scope Context
Dependency intelligence pipeline with policy gates for release readiness.
Inputs
- Policy requirements and risk appetite definition
- System boundaries and affected components
- Exception handling workflow and escalation owner
Outputs
- Control implementation with enforceable policy condition
- Monitoring signal and alerting threshold
- Exception register entry with expiry and audit trace
Acceptance Criteria
- Control blocks or flags non-compliant state changes
- Evidence is exportable for internal or external audit
- Exception path is time-bounded and explicitly approved
Compliance Evidence Notes
- [NIS2] Control objective and test outcome recorded for assurance
- [DORA] Control objective and test outcome recorded for assurance
Specification Schema
Owner Role
Security and Platform Governance Owner
Approval Sign-Off
Governance lead plus founder-level exception approval for bypasses
Versioning Policy
Policy revision tags linked to deployment release ID
Review Cadence
Bi-weekly control health review and quarterly deep audit
Evidence Retention
Control test evidence retained for at least 18 months
Required Sections
- Control objective and policy statement
- Trigger conditions and enforcement mechanism
- Monitoring signals and alert thresholds
- Exception process with expiry policy
- Control test method and result capture format