software component
163558·updated Aug 30, 2026A discrete, self-contained unit of executable code — such as a library, module, middleware, or framework — that provides a defined function or set of functions within a larger system. It is distinguished from the system as a whole by its bounded scope, its independently addressable identity (origin, version, license, known vulnerabilities), and its composability with other such units. In security, compliance, and supply-chain risk management, the field uses the expression to identify the tractable units that must be inventoried (e.g., in a Software Bill of Materials), assessed for provenance and vulnerability, and governed across the software development lifecycle.
Source
(i.e., hardware, firmware, and software components) that are critical tothe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- patch - Glossary | CSRC
- Draft NIST Special Publication 800-218 1 Secure Software Development 2
- NIST Special Publication 800-64 Revision 2, Security ...
- Web Service - Glossary | CSRC
- What Is SBOM? Why Software Component Inventory Is Gaining Momentum - Atomicorp - Own Your Security. Protect Your Data.
- Software Component definition
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A discrete, identifiable unit of executable code — such as a library, module, package, or program — that performs defined functions and can be assembled with other units to form a larger system. In NIST's framework, it is treated as a "discrete, identifiable information technology asset (e.g., hardware, software, firmware) that represents a building block of an information system." Contractually and operationally, it is understood as "a discrete part of software which provides specific functionality or performs specific functions or procedures and which can operate independently or in conjunction with other components." In security and compliance practice, the term is used at the system-inventory and supply-chain-risk level: most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, and as concerns about security and provenance grow, it is critical to understand the risks those underlying components introduce. Regulators and standards bodies therefore require organizations to enumerate software components explicitly — SBOMs are a standardized inventory of software components used in a particular product or syst
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- software components
- possessive
- software component's
- pluralpossessive
- software components'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A discrete, self-contained unit of executable code — such as a library, module, middleware, or framework — that provides a defined function or set of functions within a larger system. It is distinguished from the system as a whole by its bounded scope, its independently addressable identity (origin, version, license, known vulnerabilities), and its composability with other such units. In security, compliance, and supply-chain risk management, the field uses the expression to identify the tractable units that must be inventoried (e.g., in a Software Bill of Materials), assessed for provenance and vulnerability, and governed across the software development lifecycle.DR-088 backfill from the noun definition column