SP800-218-PO.1.1 | Define Security Requirements for Software Development | 22 |
SP800-218-PO.1.2 | Implement Security Requirements in the Toolchain | 17 |
SP800-218-PO.1.3 | Communicate Requirements to Third-Party Providers | 19 |
SP800-218-PO.2.1 | Roles and Responsibilities for Secure Development | 19 |
SP800-218-PO.2.2 | Training and Skills Maintenance | 22 |
SP800-218-PO.2.3 | Obtain Management Commitment to Secure Development | 17 |
SP800-218-PO.3.1 | Supporting Toolchain Selection | 14 |
SP800-218-PO.3.2 | Toolchain Configuration and Integration | 18 |
SP800-218-PO.3.3 | Toolchain Generates Security Artifacts | 13 |
SP800-218-PO.4.1 | Criteria for Software Security | 19 |
SP800-218-PO.4.2 | Gather and Safeguard Security Check Information | 15 |
SP800-218-PO.5.1 | Secure Development Environment Implementation | 16 |
SP800-218-PO.5.2 | Harden Development Endpoints | 18 |
SP800-218-PS.1.1 | Protect All Forms of Code from Unauthorized Modification | 20 |
SP800-218-PS.2.1 | Provide a Mechanism for Verifying Software Release Integrity | 16 |
SP800-218-PS.3.1 | Archive and Protect Released Software | 15 |
SP800-218-PS.3.2 | Software Bill of Materials | 18 |
SP800-218-PW.1.1 | Design Software to Meet Security Requirements | 22 |
SP800-218-PW.1.2 | Track Security Requirements, Risks, and Decisions | 15 |
SP800-218-PW.1.3 | Support Standardized Security Features | 18 |
SP800-218-PW.2.1 | Qualified Review of Software Design | 19 |
SP800-218-PW.4.1 | Reuse Trusted Software Components | 20 |
SP800-218-PW.4.2 | Maintain Well-Secured In-House Components | 15 |
SP800-218-PW.4.4 | Verify Acquired Components Meet Security Requirements | 20 |
SP800-218-PW.5.1 | Secure Coding Practices | 20 |
SP800-218-PW.6.1 | Configure Compilation and Build Processes Securely | 11 |
SP800-218-PW.6.2 | Configure Build Tool Security Features | 12 |
SP800-218-PW.7.1 | Code Review | 20 |
SP800-218-PW.7.2 | Perform Code Review and Analysis | 21 |
SP800-218-PW.8.1 | Executable Testing for Security | 22 |
SP800-218-PW.8.2 | Execute Security Testing | 19 |
SP800-218-PW.9.1 | Configure Software to Have Secure Settings by Default | 16 |
SP800-218-PW.9.2 | Implement and Document Secure Defaults | 15 |
SP800-218-RV.1.1 | Identify and Confirm Vulnerabilities on an Ongoing Basis | 21 |
SP800-218-RV.1.2 | Review and Analyze Code for Vulnerabilities | 19 |
SP800-218-RV.1.3 | Vulnerability Disclosure Policy | 18 |
SP800-218-RV.2.1 | Assess, Prioritize, and Remediate Vulnerabilities | 22 |
SP800-218-RV.2.2 | Develop and Implement Remediation Plans | 19 |
SP800-218-RV.3.1 | Analyze Vulnerabilities to Identify Root Causes | 11 |
SP800-218-RV.3.2 | Identify and Fix Similar Vulnerabilities | 10 |
SP800-218-RV.3.3 | Review SDLC to Prevent Recurrence | 17 |
SP800-218-RV.3.4 | Document Lessons Learned | 18 |