PW.1—Design Software to Meet Security Requirements and Mitigate Risks
>Control Description
Identify and evaluate the security requirements for the software; determine what security risks the software is likely to face during operation and how the software's design and architecture should mitigate those risks; and justify any cases where risk-based analysis indicates that security requirements should be relaxed or waived. Addressing security requirements and risks during software design (secure by design) is key for improving software security and also helps improve development efficiency.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.