BSIMM
BSIMM SSDL Touchpoints (Architecture Analysis, Code Review, Security Testing)

BSIMM CR1.4: Use automated code review tools (SAST)

Code Review. Automated code review tools (static analysis) are used so security defects are detected at scale.

Other controls in BSIMM SSDL Touchpoints (Architecture Analysis, Code Review, Security Testing)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.