OPS-05Secure Operations
Secure development
Security requirements, review and testing are part of how software is built and released.
Why it exists
Fixing design in production is the most expensive way to work.
What usually proves it
SDLC documentation, review records, test evidence.
Smaller organizations
Code review, dependency scanning, a release checklist.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC8.1
- Fully addressedISO/IEC 27001 Annex A · A.8.25
- Fully addressedNIST Cybersecurity Framework · PR.PS-06
- Fully addressedPCI DSS · 6.2
- Deliberately absentHIPAA Security Rule — No development obligations in the Security Rule.
- Partially addressedGDPR · Art. 25 — Data protection by design and by default.
- Fully addressedEU AI Act · Art. 17
- Partially addressedNIST AI Risk Management Framework · MAP 2.3 — System design documentation.