graphgrc

SCF - TDA-06.1 - Criticality Analysis

Mechanisms exist to require the developer of the system, system component or service to perform a criticality analysis at organization-defined decision points in the Secure Development Life Cycle (SDLC).

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization require the developer of the system, system component or service to perform a criticality analysis at organization-defined decision points in the Secure Development Life Cycle (SDLC)?