Under active development Content is continuously updated and improved

3.2.9Application Security Testing

>Control Description

Where feasible, static and/or dynamic scanning and testing capabilities should be used to ensure new, and/or changes to existing, systems and applications are assessed for vulnerabilities prior to release into the production environment. Security controls should also be implemented to maintain security when development and operations practices are combined through a continuous and automated development pipeline (see paragraph 2.4.2).

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.