Secure Development Lifecycle (SDLC)
- Software and product development follows an established Secure Development Lifecycle aligned to industry best practices, governed by a secure development policy.
- Security and infrastructure requirements are defined and aligned in the design phase for new applications (security “shift-left”).
- Secrets scanning is performed in code repositories, and application changes are managed through formal change control with documented approvals.
Framework Alignment: NIST CSF PR.PS; CIS Control 16; GDPR Art. 25, 32; ISO 27001:2022 A.8.25, A.8.28, A.8.4