unified

UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies

Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-29
title
Maintain secure acquisition, development, and maintenance policies
statement
Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SA-1
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    CM-1
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    MA-1
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.8
    coverage
    full
    relationship
    superset_of
  • framework
    nis2
    control_id
    NIS2-Art21e
    coverage
    partial
    delta
    operational vulnerability handling and coordinated disclosure processes
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections