Designing Secure Software Development Life Cycle(SSDLC) process

Critical
High
Normal
Low

The organization shall define and implement a Secure Software Development Life Cycle (SSDLC) process in software development.

The first step in the SSDLC process should be to define security requirements that ensure that security considerations become integrated into the services being developed right from the creation phase.

It is recommended that the SSDLC process include at least the following steps:

  • A - Training
  • B - Description of the requirements
  • C - Design
  • D - Development
  • E - Security testing
  • F - Publication
  • G - Responding to issues
Connected other frameworks and requirements:
PR.IP-2: A System Development Life Cycle
NIST CSF
9.4 (MIL2): Implement Software Security as an Element of the Cybersecurity Architecture
C2M2
9.4 (MIL3): Implement Software Security as an Element of the Cybersecurity Architecture
C2M2
No items found.