unified

UC-SDLC-04 — Engineer systems with secure architecture and design

Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Secure Development (SDLC) & Application Security
type
preventive
category
technical

Details

unified_id
UC-SDLC-04
title
Engineer systems with secure architecture and design
statement
Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.
domain
Secure Development (SDLC) & Application Security
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SA-8
    coverage
    partial
    delta
    privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    SA-17
    coverage
    partial
    delta
    developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    SC-39
    coverage
    full
    relationship
    superset_of
  • framework
    cobit-2019
    control_id
    BAI03
    coverage
    partial
    delta
    full solution build, component, and maintenance life cycle satisfied by companion controls
    relationship
    intersects_with
  • framework
    iso-27001
    control_id
    A.8.27
    coverage
    full
    relationship
    superset_of
  • framework
    eu-ai-act
    control_id
    AIA-Art15
    coverage
    partial
    delta
    AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls
    relationship
    intersects_with
  • framework
    aiuc-1
    control_id
    B008
    coverage
    partial
    delta
    hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections