AA1.1Perform security feature review
AA1.4Use a risk-ranking methodology for applications
AA2.1Perform architecture analysis using STRIDE or equivalent
AM1.2Create a data classification scheme and inventory
AM1.3Identify potential attackers
AM1.5Gather and use attack intelligence
CMVM1.1Create or use an incident response capability for software
CMVM1.2Identify software defects found in operations and feed them back to development
CMVM1.3Track software bugs found in operations through the fix process
CMVM3.4Operate a bug bounty program
CP1.1Unify regulatory pressures
CP1.2Identify privacy (PII) obligations
CP1.3Create software security policy
CR1.2Perform opportunistic code review
CR1.4Use automated code review tools (SAST)
CR1.5Make code review mandatory for all projects
PT1.1Use external penetration testers
PT1.2Feed penetration test results to defect management
PT1.3Use penetration testing tools internally
SE1.2Ensure host and network security basics are in place
SE1.3Implement cloud security controls
SE3.6Enhance application inventory with an operations bill of materials
SFD1.1Build and publish security features
SFD1.2Engage architecture teams with security
SM1.1Publish process and evolve as necessary
SM1.3Educate executives on software security
SM1.4Implement security checkpoints and associated governance gates
SM2.2Enforce gates with measurements and track exceptions
SR1.1Create security standards
SR1.3Translate compliance constraints to requirements
SR1.5Identify open source and manage its risk
ST1.1Perform edge/boundary value condition testing
ST1.3Drive tests with security requirements and features
ST1.4Integrate opportunistic security testing into the pipeline
T1.1Conduct software security awareness training
T1.7Deliver on-demand individual training