EvidenceSheet

NIST SP 800-218 (SSDF): the evidence behind every control

42 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

Prepare the Organization

PO.1.1Define Security Requirements for Software Development hardPO.1.2Implement Security Requirements in the Toolchain hardPO.2.1Roles and Responsibilities for Secure Development hardPO.2.2Training and Skills Maintenance moderatePO.3.1Supporting Toolchain Selection hardPO.3.2Toolchain Configuration and Integration easyPO.4.1Criteria for Software Security moderatePO.5.1Secure Development Environment Implementation moderate

NIST SP 800-218: Information Security Policies

PO.1.3Communicate Requirements to Third-Party Providers hardPO.2.3Obtain Management Commitment to Secure Development hardPO.3.3Toolchain Generates Security Artifacts easyPO.4.2Gather and Safeguard Security Check Information hardPO.5.2Harden Development Endpoints hard

Protect the Software

PS.1.1Protect All Forms of Code from Unauthorized Modification easyPS.2.1Provide a Mechanism for Verifying Software Release Integrity moderatePS.3.1Archive and Protect Released Software hardPS.3.2Software Bill of Materials moderate

Produce Well Secured Software

PW.1.1Design Software to Meet Security Requirements hardPW.4.1Reuse Trusted Software Components moderatePW.4.4Verify Acquired Components Meet Security Requirements moderatePW.5.1Secure Coding Practices hardPW.6.1Configure Compilation and Build Processes Securely moderatePW.7.1Code Review moderatePW.8.1Executable Testing for Security moderatePW.9.1Configure Software to Have Secure Settings by Default moderate

NIST SP 800-218: Asset Management

PW.1.2Track Security Requirements, Risks, and Decisions hardPW.1.3Support Standardized Security Features hardPW.2.1Qualified Review of Software Design hardPW.4.2Maintain Well-Secured In-House Components hardPW.6.2Configure Build Tool Security Features easy

NIST SP 800-218: Access Control

PW.7.2Perform Code Review and Analysis hardPW.8.2Execute Security Testing hardPW.9.2Implement and Document Secure Defaults hardRV.1.2Review and Analyze Code for Vulnerabilities hardRV.1.3Vulnerability Disclosure Policy hard

Respond to Vulnerabilities

RV.1.1Identify and Confirm Vulnerabilities on an Ongoing Basis moderateRV.2.1Assess, Prioritize, and Remediate Vulnerabilities hardRV.3.1Analyze Vulnerabilities to Identify Root Causes easy

NIST SP 800-218: Cryptography

RV.2.2Develop and Implement Remediation Plans hardRV.3.2Identify and Fix Similar Vulnerabilities hardRV.3.3Review SDLC to Prevent Recurrence hardRV.3.4Document Lessons Learned hard