S0048RS3-T12-S0048-Z · Full risk code

Blind Spots from Missing Component Inventory

缺乏元件清單導致漏洞盲區

Design & Development
Risk Description

When after a major vulnerability advisory is published, the organization cannot determine whether its systems use an affected version; due to unmitigated control gaps, manual inventory takes several days, during which the systems remain exposed to a known risk, and even afterward the organization cannot confirm that all dependencies were covered, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST CSF 2.0ID.RA
ISO/IEC 42001Annex A.10.3
ISO/IEC 5338設計與開發

Risk Treatment & Implementation Guidance

Maintain a software bill of materials covering AI components and all dependency versions; Automate vulnerability tracking, auto-matching affected components upon advisories; Set response deadlines for critical systems, applying mitigations during exposure