Skip to content

Security Requirement

What is Security Requirement?

A condition or capability that a system must possess to satisfy a security policy, standard, or contractual obligation.

Information Security

Each of these is named in at least one of the same controls as security requirement. The number is how many controls name both.

What the standards actually require on security requirement

Requirements naming security requirement across 6 standards, quoted from the control text.

NIST SP 800-2187 controls

Track and maintain the software's security requirements, risks, and design decisions.

SP800-218-PW.1.2 · Track Security Requirements, Risks, and Decisions

When a relevant product undergoes a material change that could affect its security compliance, the manufacturer must re-assess and, where needed, re-issue the Statement of Compliance.

PSTI-3.8 · Security Requirements Review on Product Change

The right to verify compliance with security requirements is documented in contractual arrangements with service providers.

ISM-1571 · The right to verify compliance with security requirements is documented in contractual arr
ISO 27001:20225 controls

Identify, specify and approve security requirements when developing or acquiring applications.

iso-27001-2022::8.26 · Application security requirements
BSIMM4 controls

Security Testing. Tests are driven by security requirements and features so testing verifies the controls that matter.

ST1.3 · Drive tests with security requirements and features
IEC 624434 controls

Product supplier specifies security context, threat model and security requirements for the product, traceable to design and verification activities.

62443-4-1-SR · Specification of Security Requirements

Questions people ask about security requirement

What is Security Requirement?
A condition or capability that a system must possess to satisfy a security policy, standard, or contractual obligation.
Why is Security Requirement important for compliance?
Security Requirement is a key concept in Information Security. Understanding security requirement helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Requirement?
Security Requirement appears in the requirement text of NIST SP 800-218, UK Product Security and Telecommunications Infrastructure Act (PSTI), Australian Information Security Manual, ISO 27001:2022, BSIMM. Across these standards we have identified 32 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Requirement?
Explore our compliance framework pages to see how security requirement applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Requirement applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.