Third-Party and Software Supply-Chain Risk: SCA and SBOM CySA+ V4 Domain 2 — Vulnerability Management Objective 2.4 19–23 minutes