unified
UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-29
- title
- Maintain secure acquisition, development, and maintenance policies
- statement
- Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CM-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- MA-1
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.8
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21e
- coverage
- partial
- delta
- operational vulnerability handling and coordinated disclosure processes
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
- Policy Lifecycle Management oversees UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
- Security Policy Suite Review operates UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies maps_to 500.8 — Application security
- framework
- nydfs-500
- control_id
- 500.8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies maps_to SA-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- SA-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing secure acquisition, development, configuration, and maintenance policies remedies missing policies for this domain.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies maps_to MA-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- MA-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Evaluation criteria for externally developed applications set security requirements on acquired third-party software.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies maps_to CM-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- CM-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies maps_to NIS2-Art21e — Security in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)
- framework
- nis2
- control_id
- NIS2-Art21e
- coverage
- partial
- delta
- operational vulnerability handling and coordinated disclosure processes
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.