CIS Controls v8
CIS Control 16: Application Software Security

CIS Controls v8 CIS-16.10: Apply Secure Design Principles in Application Architectures

Build secure design principles into application architecture. These include least privilege and mediation that checks every user action, in keeping with the rule never to trust user input. For example, error checking should be carried out and documented for every input, covering size, data type and permitted ranges or formats. Good design further requires shrinking the attack surface of the application infrastructure, for instance by closing unprotected ports and services, removing programs and files that are not needed, and renaming or removing default accounts.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 57 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

FedRAMP High · 5 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-8 Security and Privacy Engineering Principles
  • SC-7(5) Deny by Default Allow by Exception
  • SI-10 Information Input Validation

FedRAMP Moderate · 5 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-8 Security and Privacy Engineering Principles
  • SC-7(5) Deny by Default Allow by Exception
  • SI-10 Information Input Validation

ISO 27701:2019 · 5 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.11.2 Security in development and support processes
  • 7.4 Privacy by design and privacy by default
  • 8.4 Privacy by design and privacy by default

ISO 27001:2022 · 4 controls

  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding

PCI DSS 4.0 · 4 controls

  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.5.3 6.5.3 Separate pre-production from production
  • 7.2.5 7.2.5 Application and system accounts least privilege

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • ISM-1240 Validating and sanitising internet input
  • ISM-2034 Documenting security design decisions
  • ISM-2057 Documenting and testing input validation rules
  • CCM-AIS-02 Application Security Baseline Requirements
  • CCM-AIS-04 Secure Application Design and Development
  • CCM-DSP-07 Data Protection by Design and Default

NIST SP 800-161 Rev 1 · 3 controls

  • 161R1-PL-8 Security and Privacy Architectures
  • 161R1-SA-17 Developer Security and Privacy Architecture and Design
  • 161R1-SA-8 Security and Privacy Engineering Principles

ISO 27002:2022 · 2 controls

  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles

ISO/IEC 42001:2023 · 2 controls

  • 8.3 AI risk treatment
  • A.6.2.2 AI system requirements and specification

NIST SP 800-218 · 2 controls

C5 (Germany) · 1 control

  • C5-DEV-01 Policies for the development/procurement of information systems

CMMC 2.0 · 1 control

  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • 03.16.01 Security Engineering Principles

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 16: Application Software Security

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-16.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.