CIS Controls v8
CIS Control 16: Application Software Security

CIS Controls v8 CIS-16.1: Establish and Maintain a Secure Application Development Process

Set up and keep a process for developing applications securely that deals with matters such as standards for secure design, secure coding practice, training of developers, vulnerability management, the security of third-party code, and procedures for testing application security. Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 97 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 10 controls

ISO 27001:2022 · 8 controls

  • 5.8 Information security in project management
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.30 Outsourced development
  • 8.31 Separation of development, test and production environments
  • 8.32 Change management

FedRAMP High · 7 controls

  • AT-3 Role-Based Training
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-10 Developer Configuration Management
  • SA-11 Developer Testing and Evaluation
  • SA-15 Development Process, Standards, and Tools (SA-15)
  • SA-3 System Development Life Cycle

FedRAMP Moderate · 7 controls

  • AT-3 Role-Based Training
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-10 Developer Configuration Management
  • SA-11 Developer Testing and Evaluation
  • SA-15 Development Process, Standards, and Tools (SA-15)
  • SA-3 System Development Life Cycle

ISO 27002:2022 · 7 controls

  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.31 Separation of development, test and production environments
  • 8.32 Change management

NIST SP 800-218 · 7 controls

ISO/IEC 42001:2023 · 5 controls

  • 7.2 Competence
  • 7.5.3 Control of documented information
  • 8.3 AI risk treatment
  • A.6.2.2 AI system requirements and specification
  • A.6.2.5 AI system deployment
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP04 Conduct code reviews
  • SEC11-BP06 Deploy software programmatically
  • SEC11-BP08 Build a program that embeds security ownership in workload teams

HIPAA Security Rule · 4 controls

ISO 27701:2019 · 4 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.11.2 Security in development and support processes
  • 8.4 Privacy by design and privacy by default

PCI DSS 4.0 · 4 controls

  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.3 6.2.3 Code review before release
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.5.1 6.5.1 Change control procedure for production

SOC 2 · 4 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • ISM-0401 Secure by Design in software development
  • ISM-2033 Documenting software security requirements
  • ISM-2035 Security roles in the development life cycle

C5 (Germany) · 3 controls

  • C5-DEV-01 Policies for the development/procurement of information systems
  • C5-DEV-03 Policies for changes to information systems
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • CCM-AIS-01 Application and Interface Security Policy and Procedures
  • CCM-AIS-04 Secure Application Design and Development
  • CCM-AIS-06 Automated Secure Application Deployment

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • ASBv3-GS-10 Define and implement DevOps security strategy
  • DS-6 Enforce security of workload throughout DevOps lifecycle

CMMC 2.0 · 2 controls

  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • AUCDR-IS-4 Formal vulnerability management program
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • 03.16.01 Security Engineering Principles

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 16: Application Software Security

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-16.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 97 it maps to, and the evidence behind each claim, over MCP and REST.