{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-04","description":"Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.","details":{"control_category":"technical","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SA-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.29","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.","title":"Test software security during development and acceptance","unified_id":"UC-VULN-04"},"id":"uc:UC-VULN-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-04","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-VULN-04 — Test software security during development and acceptance","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18bb65c955dc5eb4def67fe3bfa289d5b43b767f387bd50336da8e48b9e9a170","properties":{"control_id":"SA-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-11-558f99e5.json","targetId":"ctrl:nist-800-53:SA-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5c7fc89aae4a1276b5dd306393b031f75c1f70fb45a96045104ff88e46ab95a1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","targetId":"uc:UC-VULN-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76df134f9ed3e7a81b3073ab8ae40b49adcc395ff7d97641526098d03e0e95b5","properties":{"rationale":"Development-stage analysis surfaces known-vulnerable components before they reach production.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:80b5dcf1a0401185d2ebceb311894266c3b925724abab44029a60a3f07ae66d1","properties":{"control_id":"A.8.29","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-29-e0df0522.json","targetId":"ctrl:iso-27001:A.8.29","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97693356e4ec168acdfb5d63563e72f43b71fb243889ea0d03e9a4670dbf0c78","properties":{"rationale":"Mandatory security testing at development and acceptance directly prevents software shipping without adequate testing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a98fca7383aa3850a59cb66b23b99e47621fe292b726a80ec24982fc1695b03d","properties":{"rationale":"SAST/DAST and security acceptance criteria catch and remediate vulnerabilities introduced during development before release.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b338ba0af86a893a6a8e588b0ff6d758f3b90c68309ff44e50aaee0b873f9d4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","targetId":"uc:UC-VULN-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db63e47ad82fa0aa031f9a94687e09c922a31ab3f5c5bdab1e473e755a2fd221","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","targetId":"uc:UC-VULN-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6a3467671cd7a4b7151924baecad8df0f0c18e0275fc06a74048bb1bd8274dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","targetId":"uc:UC-VULN-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f89820e3199afdd0e358903f90664edb19e5e9917f411824cd4a7b79b260574d","properties":{"rationale":"Static and dynamic testing before acceptance catches insecure patterns and unsafe dependencies in AI-generated code.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/risk-ai-insecure-generated-code-ec50f0f9.json","targetId":"risk:ai-insecure-generated-code","type":"mitigates"}],"schemaVersion":1}
