{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-04","description":"Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-8","coverage":"partial","delta":"privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"SA-17","coverage":"partial","delta":"developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"SC-39","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"BAI03","coverage":"partial","delta":"full solution build, component, and maintenance life cycle satisfied by companion controls","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"A.8.27","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"AIA-Art15","coverage":"partial","delta":"AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls","framework":"eu-ai-act","relationship":"intersects_with"},{"control_id":"B008","coverage":"partial","delta":"hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.","title":"Engineer systems with secure architecture and design","unified_id":"UC-SDLC-04"},"id":"uc:UC-SDLC-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-04","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-04 — Engineer systems with secure architecture and design","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0316b884f200d4bf9909793edcf1626a125e29c471991920a1d96d863cb9fcb6","properties":{"control_id":"SA-8","coverage":"partial","delta":"privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-8-1c5a37f1.json","targetId":"ctrl:nist-800-53:SA-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0958f175515960b2eff14c7c3c44cf5855dc4c7ea253ec951422a378ef993d65","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","targetId":"uc:UC-SDLC-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:294018791896c64a9d93a83900a6161e68d2bfea3af191c2c2be93b99dcb998c","properties":{"rationale":"Defense in depth, fail-safe defaults and execution-domain isolation limit exploitation of unknown, unpatched vulnerabilities.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ebf2a861c6d12f7b6edcb7227529309dbe9d59381a73d2b8e4984e5b1749358","properties":{"rationale":"Engineering for accuracy and robustness against errors reduces embedded model/design errors, though not pricing or complaint handling.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-ops-product-flaws-design-model-error-0c5e23f4.json","targetId":"risk:ops-product-flaws-design-model-error","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41e2f7c3bbdb79c83f3d756c399e0ab252e00ec7add49757cef7164b72148cc1","properties":{"control_id":"AIA-Art15","coverage":"partial","delta":"AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art15-c3704411.json","targetId":"ctrl:eu-ai-act:AIA-Art15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:494f71c171b62c71568247a14a50ed91f12978cf48211592b92b04d4f030328e","properties":{"control_id":"BAI03","coverage":"partial","delta":"full solution build, component, and maintenance life cycle satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","targetId":"ctrl:cobit-2019:BAI03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62a6fd6b6e2a9e76fd2322f78498159ad83a219fdb36c5d6f7523a98e64315fd","properties":{"control_id":"B008","coverage":"partial","delta":"hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","targetId":"ctrl:aiuc-1:B008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:73e5eb104c34015f296fb63ac2bb2008560ecd65505cd3f79c671885506fe803","properties":{},"sourceDetailPath":"/data/v1/records/wf-c61-3da91ad5.json","sourceId":"wf:C61","targetDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","targetId":"uc:UC-SDLC-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b434d3f4332a24a50e4a02de5ab58154be569f36a0b740d44f56d522277df90","properties":{"rationale":"Applying data-protection and least-privilege principles at the architecture stage embeds privacy/security by design and default.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-privacy-no-privacy-by-design-c9472484.json","targetId":"risk:privacy-no-privacy-by-design","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7bc3ba50c40457460213820bcd8ba51e06f04bb9b5caa381c9b67c4b15b48eb2","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","targetId":"uc:UC-SDLC-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85960d8200b60aa3aea368b25665323e724971cec88495c54332359d1ed19ace","properties":{"control_id":"SC-39","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-39-2f931bd3.json","targetId":"ctrl:nist-800-53:SC-39","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9402dae5ede19ecf9900dc5577c618d04a03d1d7e4dfd3271b19f10afd5f1f37","properties":{"rationale":"Engineering solutions to remain robust and resilient against adversarial manipulation (EU AI Act Art.15) directly hardens systems against evasion, poisoning and prompt injection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9683bcf5378e8188dbccb5dc53d801548b9a4154d44d00a4e5fd895272adfad2","properties":{"rationale":"Least privilege, isolation of execution domains and attack-surface minimization directly prevent over-privileged, broadly-exposed applications.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-sdlc-insecure-privileged-apps-ce55ff82.json","targetId":"risk:sdlc-insecure-privileged-apps","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aef38d47e614f740f0f91c5cf3893d55dd66b6a94e3dfea1f703add5e5ba9ecc","properties":{"rationale":"Fail-safe defaults and resilience against adversarial manipulation reduce successful defacement/false-data injection.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-data-corruption-integrity-loss-e771738a.json","targetId":"risk:data-corruption-integrity-loss","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccbb3f21c06f4629158e88988a492b3d2fd3b100edab47b981ba17e0db55d87d","properties":{"control_id":"SA-17","coverage":"partial","delta":"developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-17-68c18be4.json","targetId":"ctrl:nist-800-53:SA-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dcceeec6be320731d92fb2efa866b3bb71d2a6fc366ab3d58cf1f8ecd316b5f1","properties":{"rationale":"Isolation of execution domains and least privilege limit ransomware lateral spread and impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfb54cca23622370cac3ee1362b8afcbe0e6e3a1a5231882cd4327d31b9e5638","properties":{"rationale":"Least privilege and process/memory isolation contain a compromise, limiting malware's blast radius.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb9b2fc276833be22e81f68e87785ccf8cb27bd7adccf57070cac1d600ea9e8d","properties":{"control_id":"A.8.27","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-27-a4a3784c.json","targetId":"ctrl:iso-27001:A.8.27","type":"maps_to"}],"schemaVersion":1}
