{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Configuration & Change Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-04","description":"Engineer security and data-protection requirements into systems and software from design onward, applying secure coding standards, pre-release security testing, and privacy-preserving defaults such as data minimization and pseudonymization. Maintain software after release by remediating identified vulnerabilities and applying security patches within risk-based timeframes. Replace or remove software that is unsupported or no longer justified by risk.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Configuration & Change Management","guidance":[],"members":[{"control_id":"PR.PS-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GDPR-Art25","coverage":"partial","delta":"Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm","framework":"gdpr","relationship":"intersects_with"},{"control_id":"PCI-Req6","coverage":"partial","delta":"also requires protections for public-facing web applications","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Engineer security and data-protection requirements into systems and software from design onward, applying secure coding standards, pre-release security testing, and privacy-preserving defaults such as data minimization and pseudonymization. Maintain software after release by remediating identified vulnerabilities and applying security patches within risk-based timeframes. Replace or remove software that is unsupported or no longer justified by risk.","title":"Build security and privacy into software design and upkeep","unified_id":"UC-CONFIG-04"},"id":"uc:UC-CONFIG-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-04","sourceIds":["gdpr","nist-csf-2","pci-dss"],"sourceUrl":null,"title":"UC-CONFIG-04 — Build security and privacy into software design and upkeep","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01dc465a9b6e69934e28b5e632cb901a08278de3d016ef492e5e603eee7ccbe2","properties":{"control_id":"PR.PS-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ps-02-2c14bd02.json","targetId":"ctrl:nist-csf-2:PR.PS-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a230971ca35f4362a01c4861ad078e87bea0a79bdaac6d7720dda0f8cc8d033","properties":{"control_id":"GDPR-Art25","coverage":"partial","delta":"Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art25-ccf26a83.json","targetId":"ctrl:gdpr:GDPR-Art25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5667a3ac9340eae1683ddf8a31450063e6b380fa21e8a090314eb2ccd39e3308","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","targetId":"uc:UC-CONFIG-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5aa11bf91ae4883afeebd74f06cc34048edc5f4a67e8809e76791fbcdd6b1e94","properties":{"rationale":"Pre-release security testing directly mitigates releasing software with undiscovered exploitable defects.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86c55221ccf682aacab5b8d62ced760182269ad9a12206c3172238e08ea63d02","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","targetId":"uc:UC-CONFIG-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a1bedef1aaa9b750d6d6bf268da2b0d3ff78a02e84946ef8bb3957f919e4f0f","properties":{"rationale":"Engineering security from design onward with secure-coding standards is the secure-by-design defense against insecurely designed, over-privileged applications.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/risk-sdlc-insecure-privileged-apps-ce55ff82.json","targetId":"risk:sdlc-insecure-privileged-apps","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:915450fe437de9c41fe1f09784091126bfa1e23305d0e0648e4424113fa2f41e","properties":{"control_id":"PCI-Req6","coverage":"partial","delta":"also requires protections for public-facing web applications","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req6-f2566fc6.json","targetId":"ctrl:pci-dss:PCI-Req6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4b281fb09aca979ec7f5b670a9ad8396a8dc07820cb71672ed6b30da543ebc0","properties":{"rationale":"Applying security patches within risk-based timeframes and replacing unsupported software directly mitigates exploitation of known unpatched flaws.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fea58377c13abbe3a866323ab4c747656b27bb6bce0828478d7e3fa165dc37db","properties":{"rationale":"Patching and replacing unsupported software keeps systems current and patchable, contributing to maintainability; maintenance support/tooling is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/risk-tech-maintainability-breach-f075a363.json","targetId":"risk:tech-maintainability-breach","type":"mitigates"}],"schemaVersion":1}
