SV-222652r508029_rule
V-222652
SRG-APP-000516
APSC-DV-003210
CAT II
10
Address security flaws within a project plan to ensure they are tracked and addressed by management.
This requirement is meant to apply to developers or organizations that are doing application development work. If the organization managing the application is not performing or managing the development of the application the requirement is not applicable.
Ask the application representative to demonstrate how security flaws are integrated into the project plan.
If security flaws are not addressed in the project plan or there is no process to introduce security flaws into the project plan, this is a finding.
V-222652
False
APSC-DV-003210
This requirement is meant to apply to developers or organizations that are doing application development work. If the organization managing the application is not performing or managing the development of the application the requirement is not applicable.
Ask the application representative to demonstrate how security flaws are integrated into the project plan.
If security flaws are not addressed in the project plan or there is no process to introduce security flaws into the project plan, this is a finding.
M
4093