unified
UC-VULN-04 — Test software security during development and acceptance
Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Vulnerability & Patch Management
- type
- detective
- category
- technical
Details
- unified_id
- UC-VULN-04
- title
- Test software security during development and acceptance
- statement
- Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.
- domain
- Vulnerability & Patch Management
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SA-11
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.29
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-VULN-04 — Test software security during development and acceptance maps_to SA-11 — Developer Testing and Evaluation
- framework
- nist-800-53
- control_id
- SA-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-VULN-04 — Test software security during development and acceptance
- UC-VULN-04 — Test software security during development and acceptance mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Development-stage analysis surfaces known-vulnerable components before they reach production.
- UC-VULN-04 — Test software security during development and acceptance maps_to A.8.29 — Security testing in development and acceptance
- framework
- iso-27001
- control_id
- A.8.29
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-04 — Test software security during development and acceptance mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandatory security testing at development and acceptance directly prevents software shipping without adequate testing.
- UC-VULN-04 — Test software security during development and acceptance mitigates Vulnerabilities introduced during software development
- strength
- primary
- rationale
- SAST/DAST and security acceptance criteria catch and remediate vulnerabilities introduced during development before release.
- Technical Security Testing & Pentest Engagement tests UC-VULN-04 — Test software security during development and acceptance
- Secure Development & Release Security Gate operates UC-VULN-04 — Test software security during development and acceptance
- Security Control Assessment & POA&M Remediation tests UC-VULN-04 — Test software security during development and acceptance
- UC-VULN-04 — Test software security during development and acceptance mitigates Insecure AI-generated code and hallucinated or typosquatted dependencies
- strength
- related
- rationale
- Static and dynamic testing before acceptance catches insecure patterns and unsafe dependencies in AI-generated code.