unified
UC-SDLC-02 — Plan and resource development programs and projects
Manage development initiatives as governed programs and projects with defined scope, stakeholders, benefits, milestones, and risk management through delivery. Identify information security requirements during planning and allocate the resources and budget needed to fulfill them as an explicit line item.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-02
- title
- Plan and resource development programs and projects
- statement
- Manage development initiatives as governed programs and projects with defined scope, stakeholders, benefits, milestones, and risk management through delivery. Identify information security requirements during planning and allocate the resources and budget needed to fulfill them as an explicit line item.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-2
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- BAI01
- coverage
- partial
- delta
- BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- BAI11
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-02 — Plan and resource development programs and projects maps_to BAI01 — Managed Programs
- framework
- cobit-2019
- control_id
- BAI01
- coverage
- partial
- delta
- BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- IT Governance Objective Review (COBIT) oversees UC-SDLC-02 — Plan and resource development programs and projects
- UC-SDLC-02 — Plan and resource development programs and projects maps_to SA-2 — Allocation of Resources
- framework
- nist-800-53
- control_id
- SA-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-02 — Plan and resource development programs and projects mitigates Vulnerabilities introduced during software development
- strength
- related
- rationale
- Funding information-security requirements as a planning line item resources secure-dev work but is an enabler, not a first-order defense; the vulnerabilities are removed by UC-01/UC-04/UC-05.
- UC-SDLC-02 — Plan and resource development programs and projects maps_to BAI11 — Managed Projects
- framework
- cobit-2019
- control_id
- BAI11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Secure SDLC Phase-Gate Program operates UC-SDLC-02 — Plan and resource development programs and projects
- UC-SDLC-02 — Plan and resource development programs and projects mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- related
- rationale
- Allocating budget/resources for security work funds the testing/tooling that is otherwise cut for cost, an enabler of adequate testing.
- UC-SDLC-02 — Plan and resource development programs and projects mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- Identifying and resourcing privacy/security requirements at planning enables privacy engineering rather than post-launch remediation.