DEV-02—Outsourcing of the development
>Control Description
In the case of outsourced development of the cloud service (or individual system components), specifications regarding the following aspects are contractually agreed between the Cloud Service Provider and the outsourced development contractor:
• Security in software development (requirements, design, implementation, tests and verifications) in accordance with recognised standards and methods;
• Acceptance testing of the quality of the services provided in accordance with the agreed functional and non-functional requirements; and
• Providing evidence that sufficient verifications have been carried out to rule out the existence of known vulnerabilities.
Additional criteria: -
Ask AI
Configure your API key to use AI features.