unified

UC-SDLC-03 — Define and approve security requirements for applications

Elicit, analyze, document, and approve functional and non-functional requirements, including application security requirements such as authentication, authorization, input and output handling, logging, and data protection, before solution design and build, assessing feasibility and alternative options. Manage requirement changes and requirements risk, and obtain stakeholder and management approval of the final requirements.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Secure Development (SDLC) & Application Security
type
preventive
category
administrative

Details

unified_id
UC-SDLC-03
title
Define and approve security requirements for applications
statement
Elicit, analyze, document, and approve functional and non-functional requirements, including application security requirements such as authentication, authorization, input and output handling, logging, and data protection, before solution design and build, assessing feasibility and alternative options. Manage requirement changes and requirements risk, and obtain stakeholder and management approval of the final requirements.
domain
Secure Development (SDLC) & Application Security
control_type
preventive
control_category
administrative
members
  • framework
    cobit-2019
    control_id
    BAI02
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.26
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections