unified

UC-VULN-04 — Test software security during development and acceptance

Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Vulnerability & Patch Management
type
detective
category
technical

Details

unified_id
UC-VULN-04
title
Test software security during development and acceptance
statement
Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.
domain
Vulnerability & Patch Management
control_type
detective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SA-11
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.29
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections