Use up-to-date and trusted third-party software components. When possible, choose established and proven frameworks and libraries that provide adequate security. Acquire these components from trusted sources or evaluate the software for vulnerabilities before use.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-16.5 | Use Up-to-Date and Trusted Third-Party Software Components | mitigates | T1195.001 | Compromise Software Dependencies and Development Tools |
Comments
Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
References
|
| CIS-16.5 | Use Up-to-Date and Trusted Third-Party Software Components | mitigates | T1195 | Supply Chain Compromise |
Comments
Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
References
|
| CIS-16.5 | Use Up-to-Date and Trusted Third-Party Software Components | mitigates | T1195.002 | Compromise Software Supply Chain |
Comments
Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
References
|