Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.
Maintain the software code developed/used by the organisation. a) Sustain a development process which includes methodical security assessments of the code. b) Be especially aware of code with particular security significance e.g. code for i) access control, ii) traffic encryption, iii) logging, iv) parsing user input, v) buffer overflow etc. c) When using open-source code and commercial tool kits, the organisation should regularly check for new versions (ideally automatically). d) Security checks of the organisation’s own code should also be automated where appropriate when using DevOps/DevSecOps. Particularly security-relevant code (cf. previous item) should be quality-assured.
Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.
Maintain the software code developed/used by the organisation. a) Sustain a development process which includes methodical security assessments of the code. b) Be especially aware of code with particular security significance e.g. code for i) access control, ii) traffic encryption, iii) logging, iv) parsing user input, v) buffer overflow etc. c) When using open-source code and commercial tool kits, the organisation should regularly check for new versions (ideally automatically). d) Security checks of the organisation’s own code should also be automated where appropriate when using DevOps/DevSecOps. Particularly security-relevant code (cf. previous item) should be quality-assured.
In Cyberday, requirements and controls are mapped to universal tasks. A set of tasks in the same topic create a Policy, such as this one.
In Cyberday, requirements and controls are mapped to universal tasks. Each requirement is fulfilled with one or multiple tasks.
Sets the overall compliance standard or regulation your organization needs to follow.
Break down the framework into specific obligations that must be met.
Concrete actions and activities your team carries out to satisfy each requirement.
Documented rules and practices that are created and maintained as a result of completing tasks.