unified
UC-SDLC-10 — Oversee outsourced development and vet developers
Direct, monitor, and review outsourced and third-party development: contractually define secure-development requirements, intellectual property ownership, and audit rights, review deliverables against requirements, and obtain evidence of security testing. Screen developers of critical systems against defined criteria before granting them access to development environments.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-10
- title
- Oversee outsourced development and vet developers
- statement
- Direct, monitor, and review outsourced and third-party development: contractually define secure-development requirements, intellectual property ownership, and audit rights, review deliverables against requirements, and obtain evidence of security testing. Screen developers of critical systems against defined criteria before granting them access to development environments.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-21
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.30
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Contractual secure-dev requirements, deliverable review and testing evidence oversee third-party AI/component providers.
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Obtaining evidence of security testing for outsourced deliverables ensures third-party code is tested/scanned rather than shipped untested.
- Third-Party Vendor Risk Lifecycle oversees UC-SDLC-10 — Oversee outsourced development and vet developers
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates Vulnerabilities introduced during software development
- strength
- related
- rationale
- Reviewing outsourced deliverables against requirements and requiring security-testing evidence reduces vulnerabilities in third-party code.
- UC-SDLC-10 — Oversee outsourced development and vet developers maps_to SA-21 — Developer Screening
- framework
- nist-800-53
- control_id
- SA-21
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-10 — Oversee outsourced development and vet developers
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- related
- rationale
- Screening developers of critical systems and reviewing deliverables reduces malicious insertion via outsourced development.
- UC-SDLC-10 — Oversee outsourced development and vet developers maps_to A.8.30 — Outsourced development
- framework
- iso-27001
- control_id
- A.8.30
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Outsourced & Critical-Component Development Oversight operates UC-SDLC-10 — Oversee outsourced development and vet developers