{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-05","description":"Establish and enforce secure coding standards for in-house and reused code, covering common weakness classes and secure use of components. Validate all information inputs for syntax, semantics, type, length, and range at trust boundaries, rejecting or safely encoding unsafe input. Verify adherence through code review and static analysis before release.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SI-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.28","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Establish and enforce secure coding standards for in-house and reused code, covering common weakness classes and secure use of components. Validate all information inputs for syntax, semantics, type, length, and range at trust boundaries, rejecting or safely encoding unsafe input. Verify adherence through code review and static analysis before release.","title":"Enforce secure coding and input validation standards","unified_id":"UC-SDLC-05"},"id":"uc:UC-SDLC-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-05","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-05 — Enforce secure coding and input validation standards","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08ccc3c6f566452a3185340998b0e69e262201186df25a9ccff0a34dcd89c76c","properties":{"rationale":"Enforced secure-coding standards plus code review and static analysis before release directly remove exploitable coding weaknesses.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44f08fe8a2e69c15b4f3e4f545c8e982f6da33c17404c80fc48453b28e42af2b","properties":{"control_id":"SI-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-10-c16e2ed9.json","targetId":"ctrl:nist-800-53:SI-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4dfb4f9e9ede5a7868a3faef7128824fa4aa94fa1d19b18c33452b64e08fbeaf","properties":{"control_id":"A.8.28","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-28-03be11c2.json","targetId":"ctrl:iso-27001:A.8.28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:50d95fbb6889f0d7fdb1e036ecd4dcb095ce92de520eba8153febcc598d8b226","properties":{"rationale":"Fewer exploitable coding defects reduce the footholds malware uses to compromise software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:667d7350dcd7b76f1a182b14d173011d5a30181546c1a0bc21bb1bbb5a4a32a5","properties":{"rationale":"Rejecting or safely encoding unsafe input at trust boundaries is a first-order defense against prompt-injection/jailbreak inputs.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:715a57945aa72a2b45f0aa7218fe3496372c12ccbc997becdf17b236c50a41a3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c61-3da91ad5.json","sourceId":"wf:C61","targetDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","targetId":"uc:UC-SDLC-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83d5de37f0a872875b0e02b1b0dc95a2ca705a2d34b1e21a77ada399caa8c445","properties":{"rationale":"Validating all inputs for syntax/semantics/type/length/range at trust boundaries rejects malicious or untrusted data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-net-untrustworthy-input-data-6465a381.json","targetId":"risk:net-untrustworthy-input-data","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:888677bf455043d9fcd32883ebc7bc6d648f1e92fcbb457ea251c2fd06c93386","properties":{"rationale":"Input validation and safe encoding prevent injection of false-but-believable data and defacement via unsafe input.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-data-corruption-integrity-loss-e771738a.json","targetId":"risk:data-corruption-integrity-loss","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92ccfe53398bfe96fa6040b71b0e62608acba4008be8e36e030bc266ff918aa8","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","targetId":"uc:UC-SDLC-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d8569d78b96c66dc575d32d4e15791a5e47056bfb2bfe22aecc7d475999ef95","properties":{"rationale":"Verifying adherence via code review and static analysis before release is the pre-release security testing itself.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccf79837aa9b13290d566d8e6e077a6b06da511d36b26c16b86050e090c548b1","properties":{"rationale":"Secure coding reduces the count of latent, as-yet-undiscovered vulnerabilities in own code.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e78a4d35bd24379ec35c8a3737e150f0b0889825e8d4c04f79adaad5d8d9e222","properties":{"rationale":"Reducing exploitable input/coding defects narrows the initial-access vulnerabilities ransomware exploits.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eecbc007a8af48ce33def4f3af48ffc26e7ae19f42399e95702ebccd0ac394f1","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","targetId":"uc:UC-SDLC-05","type":"tests"}],"schemaVersion":1}
