BSIMM
BSIMM SSDL Touchpoints (Architecture Analysis, Code Review, Security Testing)

BSIMM AA1.4: Use a risk-ranking methodology for applications

Architecture Analysis. A risk-ranking methodology is used to prioritise applications for architecture analysis so effort focuses on the highest-risk systems.

Other controls in BSIMM SSDL Touchpoints (Architecture Analysis, Code Review, Security Testing)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.