Secure Development Lifecycle
What is Secure Development Lifecycle?
A process that integrates security practices and testing throughout every phase of software development, from design through deployment and maintenance.
Terms that appear alongside secure development lifecycle
Each of these is named in at least one of the same controls as secure development lifecycle. The number is how many controls name both.
- vulnerability 6 shared controls
- nist 5 shared controls
- cybersecurity 4 shared controls
- cisa 4 shared controls
- integrity 4 shared controls
- iec 62443 3 shared controls
- software bill of materials 3 shared controls
- audit 3 shared controls
Frameworks that govern secure development lifecycle
What the standards actually require on secure development lifecycle
Requirements naming secure development lifecycle across 6 standards, quoted from the control text.
UR E27 requires equipment manufacturers to provide Software Bill of Materials (SBOM) and demonstrate secure development. SBOM contents per CISA SBOM Minimum Elements + SPDX or CycloneDX format: component name + version + supplier + license + dependency relatio...
IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity · IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity →Operate supply chain security + secure development lifecycle (SDL) + privacy + multi-vendor trust per O-RAN WG11 Security Requirements + Open Fronthaul vendor profile + national telecom security regimes.
ORANWG11-8 · Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust →Build applications through a secure development lifecycle so the organisation's security requirements are applied at design, build, deployment and operation.
CCM-AIS-04 · Secure Application Design and Development →Govern covers third party cyber risk + supply chain + continuous improvement extending from the 5 functional elements per MSC-FAL.1/Circ.3/Rev.2 + Resolution MSC.428(98).
IMO-MSC-FAL-Govern-ThirdParty-SupplyChain-Manufacturer-Yard-PortFacility-IACS-E26-E27 · IMO MSC-FAL Govern - Third Party Cyber Risk + Supply Chain + Equipment Manufacturer + Yard + Port Facility + IACS UR E26/E27 + Continuous Improvement + Audit →Disclose and operate audit logging + integrity assurance + cybersecurity risk management features per MDS2 AUDT + IGAU + CYBR sections.
MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring · MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring →Implement technical and organisational security measures + breach notification process under Article 19 + Reglamento Articles 61-67 + INAI Recommendations on Security Measures 2018 amended 2024.
MX-LFPDPPP-Security-Breach-Notification-Reglamento-63-No-Time-Limit-INAI-Recommendations-CERT-MX · Mexico LFPDPPP Security + Breach Notification + Reglamento 63 + No Specified Time + INAI Recommendations + CERT-MX →Questions people ask about secure development lifecycle
What is Secure Development Lifecycle?
Why is Secure Development Lifecycle important for compliance?
Which compliance frameworks address Secure Development Lifecycle?
Where can I learn more about Secure Development Lifecycle?
See how Secure Development Lifecycle applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.