{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-02","description":"Manage development initiatives as governed programs and projects with defined scope, stakeholders, benefits, milestones, and risk management through delivery. Identify information security requirements during planning and allocate the resources and budget needed to fulfill them as an explicit line item.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"BAI01","coverage":"partial","delta":"BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"BAI11","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Manage development initiatives as governed programs and projects with defined scope, stakeholders, benefits, milestones, and risk management through delivery. Identify information security requirements during planning and allocate the resources and budget needed to fulfill them as an explicit line item.","title":"Plan and resource development programs and projects","unified_id":"UC-SDLC-02"},"id":"uc:UC-SDLC-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-02","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-02 — Plan and resource development programs and projects","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:030c847a1be8b9e26a68bc890c648c03d31e6d385bf1a1132c0be8f4cb1c9848","properties":{"control_id":"BAI01","coverage":"partial","delta":"BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai01-12e2e132.json","targetId":"ctrl:cobit-2019:BAI01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e9a6524a9fdd426c6ff52a1f0ec205ea072ccb2c447191c65b9438ec5f4fe70","properties":{},"sourceDetailPath":"/data/v1/records/wf-g15-1231bc14.json","sourceId":"wf:G15","targetDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","targetId":"uc:UC-SDLC-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:77273ae8394056aba2fda229684dd802e28b59a90a841dc7ba355e7d7b90b6f1","properties":{"control_id":"SA-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-2-ca121182.json","targetId":"ctrl:nist-800-53:SA-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91a928fb016afb0672b207952fd2b093ec7f9725360dc4961db1ef8c0d76d8a3","properties":{"rationale":"Funding information-security requirements as a planning line item resources secure-dev work but is an enabler, not a first-order defense; the vulnerabilities are removed by UC-01/UC-04/UC-05.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94968332499f1103f173cd77196d50bc0dcff5ac97d9906f1d4138683c245e28","properties":{"control_id":"BAI11","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai11-fbe7d977.json","targetId":"ctrl:cobit-2019:BAI11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9aa966bdf4331a61eba1afa9b6417fa3df8ef15398b836d96f846a6cf9c8c62d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c61-3da91ad5.json","sourceId":"wf:C61","targetDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","targetId":"uc:UC-SDLC-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e0e557b8c1822f1bce6009d4444d94975f5c783f5c7fa72e4e081b3c5f4b2dc","properties":{"rationale":"Allocating budget/resources for security work funds the testing/tooling that is otherwise cut for cost, an enabler of adequate testing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec0bbc5a3bc96df0c3f32e2a388c424a1d009d80e79397671e79647833af3ea6","properties":{"rationale":"Identifying and resourcing privacy/security requirements at planning enables privacy engineering rather than post-launch remediation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/risk-privacy-no-privacy-by-design-c9472484.json","targetId":"risk:privacy-no-privacy-by-design","type":"mitigates"}],"schemaVersion":1}
