Skip to content

Secure Coding

What is Secure Coding?

The practice of writing software code that is resistant to security vulnerabilities. Secure coding practices include input validation, output encoding, proper error handling, and following guidelines such as the OWASP Secure Coding Practices.

Information Security

Each of these is named in at least one of the same controls as secure coding. The number is how many controls name both.

What the standards actually require on secure coding

Requirements naming secure coding across 6 standards, quoted from the control text.

CIS Controls v83 controls

Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities. Training can include general security principles and application security standard practices.

CIS-16.9 · Train Developers in Application Security Concepts and Secure Coding
NIST SP 800-2182 controls

Follow secure coding practices for input validation, output encoding, authentication, session management, error handling, and use of secure defaults. Apply practices consistently across languages used in the organization.

SP800-218-PW.5.1 · Secure Coding Practices

Per OWASP DSOMM Implementation dimension: implement secure software development practices. Requirements include (a) maintain secure coding standards aligned to language + framework + with developer guidance + (b) conduct threat modelling at design phase + revi...

DSOMM-2 · Implementation Practices, Secure Coding, and Threat Modelling
PCI SSF1 control

Developers must follow defined secure coding practices and use approved development tools, libraries, and frameworks. Code must be reviewed for security defects before integration.

SSLC-6.1 · Secure Coding Practices

Code changes to in-scope systems receive peer review and security scanning before merge to production branches

CO-NewDev-2 · Secure Coding and Code Review

Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...

JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security

Questions people ask about secure coding

What is Secure Coding?
The practice of writing software code that is resistant to security vulnerabilities. Secure coding practices include input validation, output encoding, proper error handling, and following guidelines such as the OWASP Secure Coding Practices.
Why is Secure Coding important for compliance?
Secure Coding is a key concept in Information Security. Understanding secure coding helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Secure Coding?
Secure Coding appears in the requirement text of CIS Controls v8, NIST SP 800-218, OWASP DevSecOps Maturity Model (DSOMM), PCI SSF, SOC 1 (SSAE 18 / ISAE 3402). Across these standards we have identified 11 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Secure Coding?
Explore our compliance framework pages to see how secure coding applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Secure Coding applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.