Answer yes if your organisation can demonstrate the composition and provenance of the software it develops, including any third-party or open-source components. Upload supporting evidence such as, but not limited to: a software inventory, dependency lists, or a software bill of materials (SBOM).
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.
No organisation is an island.