AA1.1 | Perform security feature review | 1 |
AA1.4 | Use a risk-ranking methodology for applications | 1 |
AA2.1 | Perform architecture analysis using STRIDE or equivalent | 1 |
AM1.2 | Create a data classification scheme and inventory | 1 |
AM1.3 | Identify potential attackers | 1 |
AM1.5 | Gather and use attack intelligence | 1 |
CMVM1.1 | Create or use an incident response capability for software | 1 |
CMVM1.2 | Identify software defects found in operations and feed them back to development | 1 |
CMVM1.3 | Track software bugs found in operations through the fix process | 1 |
CMVM3.4 | Operate a bug bounty program | 1 |
CP1.1 | Unify regulatory pressures | 1 |
CP1.2 | Identify privacy (PII) obligations | 1 |
CP1.3 | Create software security policy | 1 |
CR1.2 | Perform opportunistic code review | 1 |
CR1.4 | Use automated code review tools (SAST) | 1 |
CR1.5 | Make code review mandatory for all projects | 1 |
PT1.1 | Use external penetration testers | 1 |
PT1.2 | Feed penetration test results to defect management | 1 |
PT1.3 | Use penetration testing tools internally | 1 |
SE1.2 | Ensure host and network security basics are in place | 1 |
SE1.3 | Implement cloud security controls | 1 |
SE3.6 | Enhance application inventory with an operations bill of materials | 1 |
SFD1.1 | Build and publish security features | 1 |
SFD1.2 | Engage architecture teams with security | 1 |
SM1.1 | Publish process and evolve as necessary | 1 |
SM1.3 | Educate executives on software security | 1 |
SM1.4 | Implement security checkpoints and associated governance gates | 1 |
SM2.2 | Enforce gates with measurements and track exceptions | 1 |
SR1.1 | Create security standards | 1 |
SR1.3 | Translate compliance constraints to requirements | 1 |
SR1.5 | Identify open source and manage its risk | 1 |
ST1.1 | Perform edge/boundary value condition testing | 1 |
ST1.3 | Drive tests with security requirements and features | 1 |
ST1.4 | Integrate opportunistic security testing into the pipeline | 1 |
T1.1 | Conduct software security awareness training | 1 |
T1.7 | Deliver on-demand individual training | 1 |