Blind Spots from Missing Component Inventory
缺乏元件清單導致漏洞盲區
Design & Development
Risk Description
When after a major vulnerability advisory is published, the organization cannot determine whether its systems use an affected version; due to unmitigated control gaps, manual inventory takes several days, during which the systems remain exposed to a known risk, and even afterward the organization cannot confirm that all dependencies were covered, triggering compliance exposure and operational reputational costs.
Framework Mappings
OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST CSF 2.0ID.RA
ISO/IEC 42001Annex A.10.3
ISO/IEC 5338設計與開發
Risk Treatment & Implementation Guidance
Maintain a software bill of materials covering AI components and all dependency versions; Automate vulnerability tracking, auto-matching affected components upon advisories; Set response deadlines for critical systems, applying mitigations during exposure