Skip to main content

SID-OPS-08 — Secure Development Lifecycle

PropertyValue
Statusto_do
Ownerplatform
Categoryprocess
CSF Functionprotect
GroupOperational Controls

Description

Documented secure SDLC: threat modeling, secure coding guidelines, code review policy, security testing requirements. Separation of development, test, and production environments. Test information management. Protection of information systems during audit testing.

Operator Responsibility

Maintain separation of deployment environments (dev/test/prod), manage deployment pipeline security, and protect audit test data.

Audit Findings

FindingSeverityStatus
EN-S-3 — Partial SDLC, change management and vulnerability scanningmediumin progress
ISO-T-3 — Secure development lifecycle gapsmediumopen