unified
UC-SDLC-01 — Follow a secure development lifecycle with approval gates
Define and follow a documented development lifecycle with security integrated into every phase from requirements through design, build, test, and release, including defined security activities, secure development standards and tooling, and management approval gates. Ensure new systems and significant changes are designed, developed, tested, and approved in accordance with management's specifications before migration to production. Monitor adherence to and performance of the secure development process.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-01
- title
- Follow a secure development lifecycle with approval gates
- statement
- Define and follow a documented development lifecycle with security integrated into every phase from requirements through design, build, test, and release, including defined security activities, secure development standards and tooling, and management approval gates. Ensure new systems and significant changes are designed, developed, tested, and approved in accordance with management's specifications before migration to production. Monitor adherence to and performance of the secure development process.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SA-15
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.PS-06
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.25
- coverage
- full
- relationship
- superset_of
- framework
- sox
- control_id
- ITGC-DEV
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates maps_to SA-15 — Development Process, Standards, and Tools
- framework
- nist-800-53
- control_id
- SA-15
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-01 — Follow a secure development lifecycle with approval gates
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates mitigates Vulnerabilities introduced during software development
- strength
- primary
- rationale
- Integrating defined security activities, secure-dev standards/tooling and testing across every lifecycle phase directly reduces vulnerabilities introduced during development.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates maps_to ITGC-DEV — Program development / SDLC — new systems and significant implementations are designed, developed, tested, approved, and converted/migrated in accordance with management's specifications.
- framework
- sox
- control_id
- ITGC-DEV
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates maps_to A.8.25 — Secure development life cycle
- framework
- iso-27001
- control_id
- A.8.25
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates mitigates Applications running with excessive privilege / insecure design
- strength
- related
- rationale
- Secure-by-design activities embedded in the lifecycle contribute to eliminating insecure/over-privileged designs, though architecture (UC-04) is the operative control.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates mitigates Absent or weak change-control procedures
- strength
- related
- rationale
- SDLC approval gates requiring significant changes be tested/approved before production contribute to change discipline, but the operative change controls are the dedicated UC-07 and UC-06 (approved-changes-only).
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandated security activities and test/approval gates before release ensure software is tested rather than shipped untested.
- Secure SDLC Phase-Gate Program operates UC-SDLC-01 — Follow a secure development lifecycle with approval gates
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates maps_to PR.PS-06 — Platform Security: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
- framework
- nist-csf-2
- control_id
- PR.PS-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates maps_to SA-3 — System Development Life Cycle
- framework
- nist-800-53
- control_id
- SA-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.