CMMC 2.0
System and Communications Protection

CMMC 2.0 SC.L2-3.13.2: Security Engineering

Apply architectural design, software development techniques and systems engineering principles that promote effective information security.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 58 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 6 controls

  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.31 Separation of development, test and production environments

PCI DSS 4.0 · 6 controls

  • 2.2.1 2.2.1 System configuration standards maintained
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches
  • 6.5.1 6.5.1 Change control procedure for production

CIS Controls v8 · 5 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.10 Apply Secure Design Principles in Application Architectures
  • CIS-16.14 Conduct Threat Modeling
  • CIS-18.1 Establish and Maintain a Penetration Testing Program

SOC 2 · 5 controls

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

NIST SP 800-218 · 4 controls

  • SEC01-BP06 Automate deployment of standard security controls
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • ASBv3-DS-1 Conduct threat modeling
  • ASBv3-GS-4 Define and implement network security strategy
  • DS-6 Enforce security of workload throughout DevOps lifecycle

FedRAMP High · 3 controls

  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

FedRAMP Moderate · 3 controls

  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

ISO 27001:2022 · 3 controls

  • 8.25 Secure development life cycle
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • ASD37-09 OS generic exploit mitigation (Excellent)
  • ASD37-24 Non-persistent virtualised sandboxed environment (Very Good)

ISO 27701:2019 · 2 controls

  • 6.11.1 Security requirements of information systems
  • 6.11.2 Security in development and support processes

NIST SP 800-172 · 2 controls

  • 3.13.2e Introduce Unpredictability into System Operations
  • 3.13.3e Confuse and Mislead Adversaries

NIST SP 800-53 Rev 5 · 2 controls

C5 (Germany) · 1 control

  • C5-DEV-01 Policies for the development/procurement of information systems
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • 161R1-SA-8 Security and Privacy Engineering Principles
  • 03.16.01 Security Engineering Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in System and Communications Protection

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 SC.L2-3.13.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.