unified

UC-CONFIG-04 — Build security and privacy into software design and upkeep

Engineer security and data-protection requirements into systems and software from design onward, applying secure coding standards, pre-release security testing, and privacy-preserving defaults such as data minimization and pseudonymization. Maintain software after release by remediating identified vulnerabilities and applying security patches within risk-based timeframes. Replace or remove software that is unsupported or no longer justified by risk.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Secure Configuration & Change Management
type
preventive
category
technical

Details

unified_id
UC-CONFIG-04
title
Build security and privacy into software design and upkeep
statement
Engineer security and data-protection requirements into systems and software from design onward, applying secure coding standards, pre-release security testing, and privacy-preserving defaults such as data minimization and pseudonymization. Maintain software after release by remediating identified vulnerabilities and applying security patches within risk-based timeframes. Replace or remove software that is unsupported or no longer justified by risk.
domain
Secure Configuration & Change Management
control_type
preventive
control_category
technical
members
  • framework
    nist-csf-2
    control_id
    PR.PS-02
    coverage
    full
    relationship
    superset_of
  • framework
    gdpr
    control_id
    GDPR-Art25
    coverage
    partial
    delta
    Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm
    relationship
    intersects_with
  • framework
    pci-dss
    control_id
    PCI-Req6
    coverage
    partial
    delta
    also requires protections for public-facing web applications
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections