Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Coding) + threat modelling (STRIDE + DREAD + PASTA) + secure design review + code review (SAST + DAST + IAST + SCA) + security testing + penetration testing prior to production + open-source license compliance + Software Bill of Materials (SBOM added 2024) + DevSecOps + CI/CD pipeline security + Infrastructure as Code (IaC) security + Terraform + Ansible + Pulumi + secret scanning + container security (image scanning + runtime protection + Falco + Aqua + Sysdig + Twistlock) + container orchestration (Kubernetes Pod Security + RBAC + Network Policies + Admission Controllers) + serverless security (function permissions + cold-start + secrets) + API security (OWASP API Top 10 + rate limiting + authentication + authorization + input validation) + microservices security (mTLS + service mesh + Istio + Linkerd + Consul). Supplier Relationships (ISO/IEC 27036) - supplier risk assessment + due diligence + contractual security requirements + audit rights + SLA + sub-supplier management + supply chain risk management + SOC 2 + ISO 27001 + ABS-OPSWAT Critical Infrastructure + cloud-native security posture management (CSPM) + cloud workload protection (CWPP) + cloud-native application protection (CNAPP). Vulnerability Management - vulnerability scanning programme + monthly external + weekly internal + container scanning + cloud configuration scanning + CVSS prioritisation + SLA remediation (critical 24-48h + high 7d + medium 30d + low 90d) + bug bounty + responsible disclosure + CVE tracking + KEV CISA Known Exploited Vulnerabilities monitoring.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.