Creation of Source Code via Adherence to Secure Coding Practices, v1.1

Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice PW.5: Creation of Source Code via Adherence to Secure Coding Practices. Requires an organization to decrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation that meet or exceed organization-defined vulnerability severity criteria.

Assessment Step

1
Adherence to Secure Coding Practices (AdherencetoSecureCodingPractices)
Does the organization follow all secure coding practices that are appropriate to the development languages and environment to meet the organization's requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Adherence to Secure Coding Practices
The organization must follow all secure coding practices that are appropriate to the development languages and environment to meet the organization's requirements.
Citation
SSDF
Task PW.5.1