home/glossary/software component

software component

nounid 163558·updated Aug 30, 2026
verified

A discrete, self-contained unit of executable code — such as a library, module, middleware, or framework — that provides a defined function or set of functions within a larger system. It is distinguished from the system as a whole by its bounded scope, its independently addressable identity (origin, version, license, known vulnerabilities), and its composability with other such units. In security, compliance, and supply-chain risk management, the field uses the expression to identify the tractable units that must be inventoried (e.g., in a Software Bill of Materials), assessed for provenance and vulnerability, and governed across the software development lifecycle.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0181
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
(i.e., hardware, firmware, and software components) that are critical tothe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A discrete, identifiable unit of executable code — such as a library, module, package, or program — that performs defined functions and can be assembled with other units to form a larger system. In NIST's framework, it is treated as a "discrete, identifiable information technology asset (e.g., hardware, software, firmware) that represents a building block of an information system." Contractually and operationally, it is understood as "a discrete part of software which provides specific functionality or performs specific functions or procedures and which can operate independently or in conjunction with other components." In security and compliance practice, the term is used at the system-inventory and supply-chain-risk level: most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, and as concerns about security and provenance grow, it is critical to understand the risks those underlying components introduce. Regulators and standards bodies therefore require organizations to enumerate software components explicitly — SBOMs are a standardized inventory of software components used in a particular product or syst

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems3 citations · 3 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.03 ¶ 403.07.04.c ¶ 203.16.02.b ¶ 2

Classifications

Entity Type

Data75%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated70%llm-generatedllm:claude-haiku-4-5

Information Class

Cui60%llm-generatedllm:claude-haiku-4-5

Variants

plural
software components
possessive
software component's
pluralpossessive
software components'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A discrete, self-contained unit of executable code — such as a library, module, middleware, or framework — that provides a defined function or set of functions within a larger system. It is distinguished from the system as a whole by its bounded scope, its independently addressable identity (origin, version, license, known vulnerabilities), and its composability with other such units. In security, compliance, and supply-chain risk management, the field uses the expression to identify the tractable units that must be inventoried (e.g., in a Software Bill of Materials), assessed for provenance and vulnerability, and governed across the software development lifecycle.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.