{
  "$TMF_VERSION": "1.4",
  "PublicationDateTime": "2025-05-15T00:00:00.000Z",
  "Description": "Profile of requirements from the NIST Secure Software Development Framework (SSDF), version 1.1.",
  "Keywords": [
    "Software Development",
    "Software Development Life Cycle",
    "SDLC",
    "Secure Software Development Framework",
    "SSDF",
    "Software Security"
  ],
  "Issuer": {
    "Identifier": "https://trustmarkinitiative.org/",
    "PrimaryContact": {
      "Email": "help@trustmarkinitiative.org",
      "Telephone": "555-555-5555",
      "Kind": "PRIMARY",
      "WebsiteURL": "https://trustmarkinitiative.org/",
      "Responder": ""
    },
    "Name": "TMI"
  },
  "Sources": [{
    "Identifier": "SSDF",
    "Reference": "NIST Special Publication 800-218, Secure Software Development Framework (SSDF), version 1.1. Published February 2022. https://doi.org/10.6028/NIST.SP.800-218.",
    "$id": "source2554594"
  }],
  "Name": "NIST SP 800-218 SSDF Compliance Profile",
  "TrustExpression": "TD_DefinitionofSecurityRequirementsforSoftwareDevelopment and TD_ImplementationofSDLCRolesandResponsibilities and TD_ImplementationofSDLCSupportingToolchains and TD_DefinitionandUseofCriteriaforSDLCSoftwareSecurityChecks and TD_ImplementationandMaintenanceofSecureEnvironmentsforSoftwareDevelopment and TD_ProtectionofAllFormsofCodefromUnauthorizedAccessandTampering and TD_ProvisionofaMechanismforVerifyingSoftwareReleaseIntegrity and TD_ArchivalandProtectionofEachSoftwareRelease and TD_DesignofSoftwaretoMeetSecurityRequirementsandMitigateSecurityRisks and TD_ReviewofSoftwareDesigntoVerifyCompliancewithSecurityRequirementsandRiskInformation and TD_ReuseofExistingWellSecuredSoftwareWhenFeasibleInsteadofDuplicatingFunctionality and TD_CreationofSourceCodeviaAdherencetoSecureCodingPractices and TD_ConfigurationofCompilationInterpreterandBuildProcessestoImproveExecutableSecurity and TD_ReviewandorAnalysisofHumanReadableCodetoIdentifyVulnerabilitiesandVerifyCompliancewithSecurityRequirements and TD_TestingofExecutableCodetoIdentifyVulnerabilitiesandVerifyCompliancewithSecurityRequirements and TD_ConfigurationofSoftwaretoHaveSecureSettingsbyDefault and TD_IdentificationandConfirmationofVulnerabilitiesonanOngoingBasis and TD_AssessmentPrioritizationandRemediationofVulnerabilities and TD_AnalysisofVulnerabilitiestoIdentifyTheirRootCauses",
  "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-218-ssdf-compliance-profile/1.1/",
  "Version": "1.1",
  "References": {"TrustmarkDefinitionRequirements": [
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/definition-of-security-requirements-for-software-development/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.1<\/b>: <i>Definition of Security Requirements for Software Development<\/i>. Requires an organization to ensure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and duplication of effort can be minimized because the requirements information can be collected once and shared. This includes requirements from internal sources (e.g., the organization's policies, business objectives, and risk management strategy) and external sources (e.g., applicable laws and regulations).",
      "Number": 1,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/definition-of-security-requirements-for-software-development/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.1<\/b>: <i>Definition of Security Requirements for Software Development<\/i>. Requires an organization to ensure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and duplication of effort can be minimized because the requirements information can be collected once and shared. This includes requirements from internal sources (e.g., the organization's policies, business objectives, and risk management strategy) and external sources (e.g., applicable laws and regulations).",
        "Number": 1,
        "Version": "1.1",
        "Name": "Definition of Security Requirements for Software Development"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Definition of Security Requirements for Software Development",
      "$id": "TD_DefinitionofSecurityRequirementsforSoftwareDevelopment"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-sdlc-roles-and-responsibilities/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.2<\/b>: <i>Implementation of SDLC Roles and Responsibilities<\/i>. Requires an organization to ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC.",
      "Number": 2,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-sdlc-roles-and-responsibilities/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.2<\/b>: <i>Implementation of SDLC Roles and Responsibilities<\/i>. Requires an organization to ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC.",
        "Number": 2,
        "Version": "1.1",
        "Name": "Implementation of SDLC Roles and Responsibilities"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Implementation of SDLC Roles and Responsibilities",
      "$id": "TD_ImplementationofSDLCRolesandResponsibilities"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-sdlc-supporting-toolchains/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.3<\/b>: <i>Implementation of SDLC Supporting Toolchains<\/i>. Requires an organization to use automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout the SDLC, as well as provide a way to document and demonstrate the use of these practices. Toolchains and tools may be used at different levels of the organization, such as organization-wide or project-specific, and may address a particular part of the SDLC, like a build pipeline.",
      "Number": 3,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-sdlc-supporting-toolchains/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.3<\/b>: <i>Implementation of SDLC Supporting Toolchains<\/i>. Requires an organization to use automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout the SDLC, as well as provide a way to document and demonstrate the use of these practices. Toolchains and tools may be used at different levels of the organization, such as organization-wide or project-specific, and may address a particular part of the SDLC, like a build pipeline.",
        "Number": 3,
        "Version": "1.1",
        "Name": "Implementation of SDLC Supporting Toolchains"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Implementation of SDLC Supporting Toolchains",
      "$id": "TD_ImplementationofSDLCSupportingToolchains"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/definition-and-use-of-criteria-for-sdlc-software-security-checks/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.4<\/b>: <i>Definition and Use of Criteria for SDLC Software Security Checks<\/i>. Requires an organization to help ensure that the software resulting from the SDLC meets the organization's expectations by defining and using criteria for checking the software's security during development.",
      "Number": 4,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/definition-and-use-of-criteria-for-sdlc-software-security-checks/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.4<\/b>: <i>Definition and Use of Criteria for SDLC Software Security Checks<\/i>. Requires an organization to help ensure that the software resulting from the SDLC meets the organization's expectations by defining and using criteria for checking the software's security during development.",
        "Number": 4,
        "Version": "1.1",
        "Name": "Definition and Use of Criteria for SDLC Software Security Checks"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Definition and Use of Criteria for SDLC Software Security Checks",
      "$id": "TD_DefinitionandUseofCriteriaforSDLCSoftwareSecurityChecks"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-and-maintenance-of-secure-environments-for-software-development/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.5<\/b>: <i>Implementation and Maintenance of Secure Environments for Software Development<\/i>. Requires an organization to ensure that all components of the environments for software development are strongly protected from internal and external threats to prevent compromises of the environments or the software being developed or maintained within them. Examples of environments for software development include development, build, test, and distribution environments.",
      "Number": 5,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/implementation-and-maintenance-of-secure-environments-for-software-development/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PO.5<\/b>: <i>Implementation and Maintenance of Secure Environments for Software Development<\/i>. Requires an organization to ensure that all components of the environments for software development are strongly protected from internal and external threats to prevent compromises of the environments or the software being developed or maintained within them. Examples of environments for software development include development, build, test, and distribution environments.",
        "Number": 5,
        "Version": "1.1",
        "Name": "Implementation and Maintenance of Secure Environments for Software Development"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Implementation and Maintenance of Secure Environments for Software Development",
      "$id": "TD_ImplementationandMaintenanceofSecureEnvironmentsforSoftwareDevelopment"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/protection-of-all-forms-of-code-from-unauthorized-access-and-tampering/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.1<\/b>: <i>Protection of All Forms of Code from Unauthorized Access and Tampering<\/i>. Requires an organization to help prevent unauthorized changes to code, both inadvertent and intentional, which could circumvent or negate the intended security characteristics of the software. For code that is not intended to be publicly accessible, this helps prevent theft of the software and may make it more difficult or time-consuming for attackers to find vulnerabilities in the software.",
      "Number": 6,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/protection-of-all-forms-of-code-from-unauthorized-access-and-tampering/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.1<\/b>: <i>Protection of All Forms of Code from Unauthorized Access and Tampering<\/i>. Requires an organization to help prevent unauthorized changes to code, both inadvertent and intentional, which could circumvent or negate the intended security characteristics of the software. For code that is not intended to be publicly accessible, this helps prevent theft of the software and may make it more difficult or time-consuming for attackers to find vulnerabilities in the software.",
        "Number": 6,
        "Version": "1.1",
        "Name": "Protection of All Forms of Code from Unauthorized Access and Tampering"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Protection of All Forms of Code from Unauthorized Access and Tampering",
      "$id": "TD_ProtectionofAllFormsofCodefromUnauthorizedAccessandTampering"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/provision-of-a-mechanism-for-verifying-software-release-integrity/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.2<\/b>: <i>Provision of a Mechanism for Verifying Software Release Integrity<\/i>. Requires an organization to help software acquirers ensure that the software they acquire is legitimate and has not been tampered with.",
      "Number": 7,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/provision-of-a-mechanism-for-verifying-software-release-integrity/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.2<\/b>: <i>Provision of a Mechanism for Verifying Software Release Integrity<\/i>. Requires an organization to help software acquirers ensure that the software they acquire is legitimate and has not been tampered with.",
        "Number": 7,
        "Version": "1.1",
        "Name": "Provision of a Mechanism for Verifying Software Release Integrity"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Provision of a Mechanism for Verifying Software Release Integrity",
      "$id": "TD_ProvisionofaMechanismforVerifyingSoftwareReleaseIntegrity"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/archival-and-protection-of-each-software-release/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.3<\/b>: <i>Archival and Protection of Each Software Release<\/i>. Requires an organization to preserve software releases in order to help identify, analyze, and eliminate vulnerabilities discovered in the software after release.",
      "Number": 8,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/archival-and-protection-of-each-software-release/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PS.3<\/b>: <i>Archival and Protection of Each Software Release<\/i>. Requires an organization to preserve software releases in order to help identify, analyze, and eliminate vulnerabilities discovered in the software after release.",
        "Number": 8,
        "Version": "1.1",
        "Name": "Archival and Protection of Each Software Release"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Archival and Protection of Each Software Release",
      "$id": "TD_ArchivalandProtectionofEachSoftwareRelease"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/design-of-software-to-meet-security-requirements-and-mitigate-security-risks/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.1<\/b>: <i>Design of Software to Meet Security Requirements and Mitigate Security Risks<\/i>. Requires an organization to identify and evaluate the security requirements for the software; determine what security risks the software is likely to face during operation and how the software's design and architecture should mitigate those risks; and justify any cases where risk-based analysis indicates that security requirements should be relaxed or waived. Addressing security requirements and risks during software design (secure by design) is key for improving software security and also helps improve development efficiency.",
      "Number": 9,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/design-of-software-to-meet-security-requirements-and-mitigate-security-risks/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.1<\/b>: <i>Design of Software to Meet Security Requirements and Mitigate Security Risks<\/i>. Requires an organization to identify and evaluate the security requirements for the software; determine what security risks the software is likely to face during operation and how the software's design and architecture should mitigate those risks; and justify any cases where risk-based analysis indicates that security requirements should be relaxed or waived. Addressing security requirements and risks during software design (secure by design) is key for improving software security and also helps improve development efficiency.",
        "Number": 9,
        "Version": "1.1",
        "Name": "Design of Software to Meet Security Requirements and Mitigate Security Risks"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Design of Software to Meet Security Requirements and Mitigate Security Risks",
      "$id": "TD_DesignofSoftwaretoMeetSecurityRequirementsandMitigateSecurityRisks"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/review-of-software-design-to-verify-compliance-with-security-requirements-and-risk-information/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.2<\/b>: <i>Review of Software Design to Verify Compliance with Security Requirements and Risk Information<\/i>. Requires an organization to help ensure that the software will meet the security requirements and satisfactorily address the identified risk information.",
      "Number": 10,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/review-of-software-design-to-verify-compliance-with-security-requirements-and-risk-information/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.2<\/b>: <i>Review of Software Design to Verify Compliance with Security Requirements and Risk Information<\/i>. Requires an organization to help ensure that the software will meet the security requirements and satisfactorily address the identified risk information.",
        "Number": 10,
        "Version": "1.1",
        "Name": "Review of Software Design to Verify Compliance with Security Requirements and Risk Information"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Review of Software Design to Verify Compliance with Security Requirements and Risk Information",
      "$id": "TD_ReviewofSoftwareDesigntoVerifyCompliancewithSecurityRequirementsandRiskInformation"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/reuse-of-existing-well-secured-software-when-feasible-instead-of-duplicating-functionality/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.4<\/b>: <i>Reuse of Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality<\/i>. Requires an organization to lower the costs of software development, expedite software development, and decrease the likelihood of introducing additional security vulnerabilities into the software by reusing software modules and services that have already had their security posture checked. This is particularly important for software that implements security functionality, such as cryptographic modules and protocols.",
      "Number": 11,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/reuse-of-existing-well-secured-software-when-feasible-instead-of-duplicating-functionality/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.4<\/b>: <i>Reuse of Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality<\/i>. Requires an organization to lower the costs of software development, expedite software development, and decrease the likelihood of introducing additional security vulnerabilities into the software by reusing software modules and services that have already had their security posture checked. This is particularly important for software that implements security functionality, such as cryptographic modules and protocols.",
        "Number": 11,
        "Version": "1.1",
        "Name": "Reuse of Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Reuse of Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality",
      "$id": "TD_ReuseofExistingWellSecuredSoftwareWhenFeasibleInsteadofDuplicatingFunctionality"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/creation-of-source-code-via-adherence-to-secure-coding-practices/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.5<\/b>: <i>Creation of Source Code via Adherence to Secure Coding Practices<\/i>. Requires an organization to decrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation that meet or exceed organization-defined vulnerability severity criteria.",
      "Number": 12,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/creation-of-source-code-via-adherence-to-secure-coding-practices/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.5<\/b>: <i>Creation of Source Code via Adherence to Secure Coding Practices<\/i>. Requires an organization to decrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation that meet or exceed organization-defined vulnerability severity criteria.",
        "Number": 12,
        "Version": "1.1",
        "Name": "Creation of Source Code via Adherence to Secure Coding Practices"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Creation of Source Code via Adherence to Secure Coding Practices",
      "$id": "TD_CreationofSourceCodeviaAdherencetoSecureCodingPractices"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/configuration-of-compilation-interpreter-and-build-processes-to-improve-executable-security/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.6<\/b>: <i>Configuration of Compilation, Interpreter, and Build Processes to Improve Executable Security<\/i>. Requires an organization to decrease the number of security vulnerabilities in the software and reduce costs by eliminating vulnerabilities before testing occurs.",
      "Number": 13,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/configuration-of-compilation-interpreter-and-build-processes-to-improve-executable-security/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.6<\/b>: <i>Configuration of Compilation, Interpreter, and Build Processes to Improve Executable Security<\/i>. Requires an organization to decrease the number of security vulnerabilities in the software and reduce costs by eliminating vulnerabilities before testing occurs.",
        "Number": 13,
        "Version": "1.1",
        "Name": "Configuration of Compilation, Interpreter, and Build Processes to Improve Executable Security"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Configuration of Compilation, Interpreter, and Build Processes to Improve Executable Security",
      "$id": "TD_ConfigurationofCompilationInterpreterandBuildProcessestoImproveExecutableSecurity"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/review-and-or-analysis-of-human-readable-code-to-identify-vulnerabilities-and-verify-compliance-with-security-requirements/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.7<\/b>: <i>Review and/or Analysis of Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements<\/i>. Requires an organization to help identify vulnerabilities so that they can be corrected before the software is released to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities. Human-readable code includes source code, scripts, and any other form of code that an organization deems human-readable.",
      "Number": 14,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/review-and-or-analysis-of-human-readable-code-to-identify-vulnerabilities-and-verify-compliance-with-security-requirements/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.7<\/b>: <i>Review and/or Analysis of Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements<\/i>. Requires an organization to help identify vulnerabilities so that they can be corrected before the software is released to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities. Human-readable code includes source code, scripts, and any other form of code that an organization deems human-readable.",
        "Number": 14,
        "Version": "1.1",
        "Name": "Review and/or Analysis of Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Review and/or Analysis of Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements",
      "$id": "TD_ReviewandorAnalysisofHumanReadableCodetoIdentifyVulnerabilitiesandVerifyCompliancewithSecurityRequirements"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/testing-of-executable-code-to-identify-vulnerabilities-and-verify-compliance-with-security-requirements/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.8<\/b>: <i>Testing of Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements<\/i>. Requires an organization to help identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities and improves traceability and repeatability. Executable code includes binaries, directly executed bytecode and source code, and any other form of code that an organization deems executable.",
      "Number": 15,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/testing-of-executable-code-to-identify-vulnerabilities-and-verify-compliance-with-security-requirements/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.8<\/b>: <i>Testing of Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements<\/i>. Requires an organization to help identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities and improves traceability and repeatability. Executable code includes binaries, directly executed bytecode and source code, and any other form of code that an organization deems executable.",
        "Number": 15,
        "Version": "1.1",
        "Name": "Testing of Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Testing of Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements",
      "$id": "TD_TestingofExecutableCodetoIdentifyVulnerabilitiesandVerifyCompliancewithSecurityRequirements"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/configuration-of-software-to-have-secure-settings-by-default/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.9<\/b>: <i>Configuration of Software to Have Secure Settings by Default<\/i>. Requires an organization to help improve the security of the software at the time of installation to reduce the likelihood of the software being deployed with weak security settings, putting it at greater risk of compromise.",
      "Number": 16,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/configuration-of-software-to-have-secure-settings-by-default/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>PW.9<\/b>: <i>Configuration of Software to Have Secure Settings by Default<\/i>. Requires an organization to help improve the security of the software at the time of installation to reduce the likelihood of the software being deployed with weak security settings, putting it at greater risk of compromise.",
        "Number": 16,
        "Version": "1.1",
        "Name": "Configuration of Software to Have Secure Settings by Default"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Configuration of Software to Have Secure Settings by Default",
      "$id": "TD_ConfigurationofSoftwaretoHaveSecureSettingsbyDefault"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/identification-and-confirmation-of-vulnerabilities-on-an-ongoing-basis/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.1<\/b>: <i>Identification and Confirmation of Vulnerabilities on an Ongoing Basis<\/i>. Requires an organization to help ensure that vulnerabilities are identified more quickly so that they can be remediated more quickly in accordance with risk, reducing the window of opportunity for attackers.",
      "Number": 17,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/identification-and-confirmation-of-vulnerabilities-on-an-ongoing-basis/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.1<\/b>: <i>Identification and Confirmation of Vulnerabilities on an Ongoing Basis<\/i>. Requires an organization to help ensure that vulnerabilities are identified more quickly so that they can be remediated more quickly in accordance with risk, reducing the window of opportunity for attackers.",
        "Number": 17,
        "Version": "1.1",
        "Name": "Identification and Confirmation of Vulnerabilities on an Ongoing Basis"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Identification and Confirmation of Vulnerabilities on an Ongoing Basis",
      "$id": "TD_IdentificationandConfirmationofVulnerabilitiesonanOngoingBasis"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/assessment--prioritization--and-remediation-of-vulnerabilities/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.2<\/b>: <i>Assessment, Prioritization, and Remediation of Vulnerabilities<\/i>. Requires an organization to help ensure that vulnerabilities are remediated in accordance with risk to reduce the window of opportunity for attackers.",
      "Number": 18,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/assessment--prioritization--and-remediation-of-vulnerabilities/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.2<\/b>: <i>Assessment, Prioritization, and Remediation of Vulnerabilities<\/i>. Requires an organization to help ensure that vulnerabilities are remediated in accordance with risk to reduce the window of opportunity for attackers.",
        "Number": 18,
        "Version": "1.1",
        "Name": "Assessment, Prioritization, and Remediation of Vulnerabilities"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Assessment, Prioritization, and Remediation of Vulnerabilities",
      "$id": "TD_AssessmentPrioritizationandRemediationofVulnerabilities"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/analysis-of-vulnerabilities-to-identify-their-root-causes/1.1/",
      "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.3<\/b>: <i>Analysis of Vulnerabilities to Identify Their Root Causes<\/i>. Requires an organization to help reduce the frequency of vulnerabilities in the future.",
      "Number": 19,
      "Version": "1.1",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/analysis-of-vulnerabilities-to-identify-their-root-causes/1.1/",
        "Description": "Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice <b>RV.3<\/b>: <i>Analysis of Vulnerabilities to Identify Their Root Causes<\/i>. Requires an organization to help reduce the frequency of vulnerabilities in the future.",
        "Number": 19,
        "Version": "1.1",
        "Name": "Analysis of Vulnerabilities to Identify Their Root Causes"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Analysis of Vulnerabilities to Identify Their Root Causes",
      "$id": "TD_AnalysisofVulnerabilitiestoIdentifyTheirRootCauses"
    }
  ]},
  "Primary": "true",
  "LegalNotice": "This artifact is published by the Georgia Tech Research Institute (GTRI) as part of the Trustmark Initiative. This artifact and the information contained herein is provided on an \"AS IS\" basis, and GTRI disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, GTRI disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.",
  "$Type": "TrustInteroperabilityProfile"
}