Implementation and Maintenance of Secure Environments for Software Development, v1.1
Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice PO.5: Implementation and Maintenance of Secure Environments for Software Development. Requires an organization to ensure that all components of the environments for software development are strongly protected from internal and external threats to prevent compromises of the environments or the software being developed or maintained within them. Examples of environments for software development include development, build, test, and distribution environments.
Assessment Steps (2)
1
Separation and Protection of Development Environments (SeparationandProtectionofDevelopmentEnvironments)
Does the organization separate and protect each environment involved in software development?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
2
Hardening of Development Endpoints (HardeningofDevelopmentEndpoints)
Does the organization secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related tasks using a risk-based approach?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (2)
Separation and Protection of Development Environments
The organization must separate and protect each environment involved in software development.
Citation
SSDF
Task PO.5.1
|
Hardening of Development Endpoints
The organization must secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related tasks using a risk-based approach.
Citation
SSDF
Task PO.5.2
|