Requirement Text
Article 10 of the accompanying DORA Technical Standards Document requires, in part, that covered entities track:
(i) third-party libraries, including open-source libraries, used by ICT services supporting critical or important functions;
(ii) ICT services developed by the financial entity itself or specifically customised or developed for the financial entity by an ICT third-party service provider;
Additionally, the standards document document requires organizations to track component "version and possible updates."