graphgrc

SCF - IAO-04 - Threat Analysis & Flaw Remediation During Development

Mechanisms exist to require system developers and integrators to create and execute a Security Test and Evaluation (ST&E) plan to identify and remediate flaws during development.

Mapped framework controls

ISO 27002

SOC 2

Control questions

Does the organization require system developers and integrators to create and execute a Security Test and Evaluation (ST&E) plan to identify and remediate flaws during development?