From a day-to-day perspective of requirements for Secure Software Development Practices (SSDP), there are “industry-recognized secure practices” that require secure software development. These frameworks impact nearly every organization, regardless of the industry it serves.
This page identifies the most common application security controls from leading cybersecurity frameworks. These requirements may come in the form of statutory, regulatory or contractual obligations for an organization to comply with.
Use this reference to:
Selected controls below — see the SCA-BoK for the comprehensive mapping.
Selected requirements for enhancing software supply chain security:
Selected requirements for bespoke and custom software development:
Beyond EO 14028, PCI DSS, CIS, and CMMC, secure software development requirements show up across most major cybersecurity frameworks. The SCA-BoK references the following.