NIST SP 800-218 (SSDF): the evidence behind every control
42 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
Prepare the Organization
PO.1.1Define Security Requirements for Software Development hardPO.1.2Implement Security Requirements in the Toolchain hardPO.2.1Roles and Responsibilities for Secure Development hardPO.2.2Training and Skills Maintenance moderatePO.3.1Supporting Toolchain Selection hardPO.3.2Toolchain Configuration and Integration easyPO.4.1Criteria for Software Security moderatePO.5.1Secure Development Environment Implementation moderateNIST SP 800-218: Information Security Policies
PO.1.3Communicate Requirements to Third-Party Providers hardPO.2.3Obtain Management Commitment to Secure Development hardPO.3.3Toolchain Generates Security Artifacts easyPO.4.2Gather and Safeguard Security Check Information hardPO.5.2Harden Development Endpoints hardProtect the Software
PS.1.1Protect All Forms of Code from Unauthorized Modification easyPS.2.1Provide a Mechanism for Verifying Software Release Integrity moderatePS.3.1Archive and Protect Released Software hardPS.3.2Software Bill of Materials moderateProduce Well Secured Software
PW.1.1Design Software to Meet Security Requirements hardPW.4.1Reuse Trusted Software Components moderatePW.4.4Verify Acquired Components Meet Security Requirements moderatePW.5.1Secure Coding Practices hardPW.6.1Configure Compilation and Build Processes Securely moderatePW.7.1Code Review moderatePW.8.1Executable Testing for Security moderatePW.9.1Configure Software to Have Secure Settings by Default moderateNIST SP 800-218: Asset Management
PW.1.2Track Security Requirements, Risks, and Decisions hardPW.1.3Support Standardized Security Features hardPW.2.1Qualified Review of Software Design hardPW.4.2Maintain Well-Secured In-House Components hardPW.6.2Configure Build Tool Security Features easyNIST SP 800-218: Access Control
PW.7.2Perform Code Review and Analysis hardPW.8.2Execute Security Testing hardPW.9.2Implement and Document Secure Defaults hardRV.1.2Review and Analyze Code for Vulnerabilities hardRV.1.3Vulnerability Disclosure Policy hardRespond to Vulnerabilities
RV.1.1Identify and Confirm Vulnerabilities on an Ongoing Basis moderateRV.2.1Assess, Prioritize, and Remediate Vulnerabilities hardRV.3.1Analyze Vulnerabilities to Identify Root Causes easy