{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-01","description":"Define and follow a documented development lifecycle with security integrated into every phase from requirements through design, build, test, and release, including defined security activities, secure development standards and tooling, and management approval gates. Ensure new systems and significant changes are designed, developed, tested, and approved in accordance with management's specifications before migration to production. Monitor adherence to and performance of the secure development process.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SA-15","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.PS-06","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.8.25","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"ITGC-DEV","coverage":"full","framework":"sox","relationship":"superset_of"}],"statement":"Define and follow a documented development lifecycle with security integrated into every phase from requirements through design, build, test, and release, including defined security activities, secure development standards and tooling, and management approval gates. Ensure new systems and significant changes are designed, developed, tested, and approved in accordance with management's specifications before migration to production. Monitor adherence to and performance of the secure development process.","title":"Follow a secure development lifecycle with approval gates","unified_id":"UC-SDLC-01"},"id":"uc:UC-SDLC-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-01","sourceIds":["iso-27001","nist-800-53","nist-csf-2","sox"],"sourceUrl":null,"title":"UC-SDLC-01 — Follow a secure development lifecycle with approval gates","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e322fde2bd4e3242feb4924d9458b75708626e46b4445864facc0af7a9a7b6b","properties":{"control_id":"SA-15","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-15-4d1e2b61.json","targetId":"ctrl:nist-800-53:SA-15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d50047c24498448c2a819dbf0343636fa27ff6caa5e9ac0d2920f143fbe2fcd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","targetId":"uc:UC-SDLC-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:659cee6499f1e52f36c512c85e4ea53d38dcc186b9e90cc423bb48e9224d9529","properties":{"rationale":"Integrating defined security activities, secure-dev standards/tooling and testing across every lifecycle phase directly reduces vulnerabilities introduced during development.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a2dd113f43050cd25f72fd6dd5f4123ced3610ac943a4b9f8f3372301e66f51","properties":{"control_id":"ITGC-DEV","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-dev-b45239b7.json","targetId":"ctrl:sox:ITGC-DEV","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d5e344a30149135e006ecccf476eb173557ce440799713ad29392ae13c3c7b7","properties":{"control_id":"A.8.25","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-25-3cbe2191.json","targetId":"ctrl:iso-27001:A.8.25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a65cb072c7f39c03229a3bab191d47560f0ab1b1042087e0a796d66348d86ffa","properties":{"rationale":"Secure-by-design activities embedded in the lifecycle contribute to eliminating insecure/over-privileged designs, though architecture (UC-04) is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-sdlc-insecure-privileged-apps-ce55ff82.json","targetId":"risk:sdlc-insecure-privileged-apps","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bca9506a16c42dad9a6c1fe955d3c973f5c1b3ccd45b1901696f0d8da676c081","properties":{"rationale":"SDLC approval gates requiring significant changes be tested/approved before production contribute to change discipline, but the operative change controls are the dedicated UC-07 and UC-06 (approved-changes-only).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cebed2c98d42090e10871e699dfc86b2cc7c26932e04018a0099a02ae9fefa28","properties":{"rationale":"Mandated security activities and test/approval gates before release ensure software is tested rather than shipped untested.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:df229cbae774092024579a9579007487113fd5017f9159cb45454c685dc346f6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c61-3da91ad5.json","sourceId":"wf:C61","targetDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","targetId":"uc:UC-SDLC-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef4ad5afde784076fff601972b9572414dad06fea23cf0deff696882568c9abe","properties":{"control_id":"PR.PS-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ps-06-48e34161.json","targetId":"ctrl:nist-csf-2:PR.PS-06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fbfe87817d7dd6e2916595aeadbc972de09d88fcfca853d5d6606b23a25f8c21","properties":{"control_id":"SA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-3-72d23e97.json","targetId":"ctrl:nist-800-53:SA-3","type":"maps_to"}],"schemaVersion":1}
