unified
UC-SDLC-04 — Engineer systems with secure architecture and design
Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- technical
Details
- unified_id
- UC-SDLC-04
- title
- Engineer systems with secure architecture and design
- statement
- Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SA-8
- coverage
- partial
- delta
- privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- SA-17
- coverage
- partial
- delta
- developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- SC-39
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- BAI03
- coverage
- partial
- delta
- full solution build, component, and maintenance life cycle satisfied by companion controls
- relationship
- intersects_with
- framework
- iso-27001
- control_id
- A.8.27
- coverage
- full
- relationship
- superset_of
- framework
- eu-ai-act
- control_id
- AIA-Art15
- coverage
- partial
- delta
- AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- B008
- coverage
- partial
- delta
- hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to SA-8 — Security and Privacy Engineering Principles
- framework
- nist-800-53
- control_id
- SA-8
- coverage
- partial
- delta
- privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Technical Security Testing & Pentest Engagement tests UC-SDLC-04 — Engineer systems with secure architecture and design
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Zero-day exploitation
- strength
- primary
- rationale
- Defense in depth, fail-safe defaults and execution-domain isolation limit exploitation of unknown, unpatched vulnerabilities.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Product design and model errors
- strength
- related
- rationale
- Engineering for accuracy and robustness against errors reduces embedded model/design errors, though not pricing or complaint handling.
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to AIA-Art15 — Accuracy, robustness and cybersecurity (high-risk)
- framework
- eu-ai-act
- control_id
- AIA-Art15
- coverage
- partial
- delta
- AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls
- relationship
- intersects_with
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to BAI03 — Managed Solutions Identification and Build
- framework
- cobit-2019
- control_id
- BAI03
- coverage
- partial
- delta
- full solution build, component, and maintenance life cycle satisfied by companion controls
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to B008 — Protect AI system deployment environment
- framework
- aiuc-1
- control_id
- B008
- coverage
- partial
- delta
- hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Secure SDLC Phase-Gate Program operates UC-SDLC-04 — Engineer systems with secure architecture and design
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Absence of privacy-by-design and default
- strength
- primary
- rationale
- Applying data-protection and least-privilege principles at the architecture stage embeds privacy/security by design and default.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-04 — Engineer systems with secure architecture and design
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to SC-39 — Process Isolation
- framework
- nist-800-53
- control_id
- SC-39
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Adversarial attacks, data poisoning and prompt injection
- strength
- primary
- rationale
- Engineering solutions to remain robust and resilient against adversarial manipulation (EU AI Act Art.15) directly hardens systems against evasion, poisoning and prompt injection.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Applications running with excessive privilege / insecure design
- strength
- primary
- rationale
- Least privilege, isolation of execution domains and attack-surface minimization directly prevent over-privileged, broadly-exposed applications.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Corruption or integrity loss of critical data
- strength
- related
- rationale
- Fail-safe defaults and resilience against adversarial manipulation reduce successful defacement/false-data injection.
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to SA-17 — Developer Security and Privacy Architecture and Design
- framework
- nist-800-53
- control_id
- SA-17
- coverage
- partial
- delta
- developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Ransomware disrupting operations and data availability
- strength
- related
- rationale
- Isolation of execution domains and least privilege limit ransomware lateral spread and impact.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Least privilege and process/memory isolation contain a compromise, limiting malware's blast radius.
- UC-SDLC-04 — Engineer systems with secure architecture and design maps_to A.8.27 — Secure system architecture and engineering principles
- framework
- iso-27001
- control_id
- A.8.27
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.