8.26 Application security requirements
Requires information security requirements to be identified, specified and approved when applications are being developed or acquired.
5
artefacts
2
held by a system
2
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Documented and approved security requirements for applications delivered in the period, covering authentication, authorisation, data protection, logging and error handling · Identity provider / directory
- Evidence covering acquired and software as a service applications, where requirements become procurement and configuration criteria · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Evidence requirements were derived from risk, from the data classification and from applicable legal obligations · Data governance / DLP tooling
- Evidence of verification that delivered applications meet the approved requirements · Document repository
governing documentDocuments that govern the control
- The method for identifying security requirements for applications, whether developed or acquired · Document repository
First move
Start with the 2 of 5 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Requirements written generically and copied between projects, so none reflect the actual data or threat
- Acquired software exempted, so most of the application estate has no security requirements at all
- Requirements approved and never verified against the delivered product
- Transaction level requirements such as integrity, non repudiation and audit trail omitted entirely
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.25 Secure development life cycle · 8.27 Secure system architecture and engineering principles