OPS-05Secure Operations

Secure development

Security requirements, review and testing are part of how software is built and released.

Why it exists

Fixing design in production is the most expensive way to work.

What usually proves it

SDLC documentation, review records, test evidence.

Smaller organizations

Code review, dependency scanning, a release checklist.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC8.1
  • Fully addressedISO/IEC 27001 Annex A · A.8.25
  • Fully addressedNIST Cybersecurity Framework · PR.PS-06
  • Fully addressedPCI DSS · 6.2
  • Deliberately absentHIPAA Security Rule — No development obligations in the Security Rule.
  • Partially addressedGDPR · Art. 25 — Data protection by design and by default.
  • Fully addressedEU AI Act · Art. 17
  • Partially addressedNIST AI Risk Management Framework · MAP 2.3 — System design documentation.