Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.PS-06 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-06: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 158 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.8 Information security in project management 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.29 Security testing in development and acceptance 8.30 Outsourced development 8.31 Separation of development, test and production environments 5.8 Information security in project management 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.29 Security testing in development and acceptance 8.30 Outsourced development 8.31 Separation of development, test and production environments CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-16.10 Apply Secure Design Principles in Application Architectures CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-16.12 Implement Code-Level Security Checks CIS-16.14 Conduct Threat Modeling CIS-16.8 Separate Production and Non-Production Systems CIS-16.9 Train Developers in Application Security Concepts and Secure Coding CM-4(2) Impact Analyses | Verification of Controls (CM-4(2)) SA-11 Developer Testing and Evaluation SA-11(1) Developer Testing and Evaluation | Static Code Analysis (SA-11(1)) SA-15 Development Process, Standards, and Tools (SA-15) SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3)) SA-3 System Development Life Cycle SA-8 Security and Privacy Engineering Principles CM-4(2) Impact Analyses | Verification of Controls (CM-4(2)) SA-11 Developer Testing and Evaluation SA-11(1) Developer Testing and Evaluation | Static Code Analysis (SA-11(1)) SA-15 Development Process, Standards, and Tools (SA-15) SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3)) SA-3 System Development Life Cycle SA-8 Security and Privacy Engineering Principles 6.2.1 6.2.1 Secure development of bespoke and custom software 6.2.3 6.2.3 Code review before release 6.2.3.1 6.2.3.1 Manual code review independence and approval 6.2.4 6.2.4 Engineering techniques against common software attacks 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.5.1 6.5.1 Change control procedure for production 6.5.3 6.5.3 Separate pre-production from production CCM-AIS-01 Application and Interface Security Policy and Procedures CCM-AIS-04 Secure Application Design and Development CCM-AIS-05 Automated Application Security Testing CCM-AIS-06 Automated Secure Application Deployment CCM-DSP-07 Data Protection by Design and Default CCM-DSP-08 Data Privacy by Design and Default SEC11-BP01 Train for application security SEC11-BP02 Automate testing throughout the development and release lifecycle SEC11-BP04 Conduct code reviews SEC11-BP06 Deploy software programmatically SEC11-BP07 Regularly assess security properties of the pipelines ASBv3-DS-3 Secure DevOps infrastructure ASBv3-DS-4 Integrate static application security testing into DevOps pipeline ASBv3-DS-5 Integrate dynamic application security testing into DevOps pipeline ASBv3-GS-10 Define and implement DevOps security strategy DS-6 Enforce security of workload throughout DevOps lifecycle ISM-0400 Segregating software environments ISM-0401 Secure by Design in software development ISM-0402 SAST, DAST and SCA testing ISM-1780 SecDevOps practices for software development SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure 6.11 Systems acquisition, development and maintenance 6.11.1 Security requirements of information systems 6.11.2 Security in development and support processes 3.13.2e Introduce Unpredictability into System Operations 3.14.1e Verify Integrity of Security Critical Software and Firmware PMF-SP.3 Security Testing and Monitoring ANSSI-HYG-01 Train Operational Teams in Information System Security APPI-A31 Provision of Personally Referable Information AUCDR-IS-4 Formal vulnerability management program BH-PDPL-18 Regular security testing and assessment CFTC-SS-5 Systems Development and Quality Assurance Category FFIEC-08 Application security controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) 27400-6.3 Secure Update Mechanism A.6.1.3 Processes for responsible design and development of AI systems Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance 03.16.01 Security Engineering Principles PR.PS-06 PR.PS-06 Secure development practices cover responding to vulnerabilities and incidents in released software NJDPA-6 Reasonable Data Security and Incident Response ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling PCI-P2PE-08 Application security controls PCI-PIN-08 Application security controls PCI-SSF-08 Application security controls PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-4 Children's Data, Privacy Impact, Sensitive Categories NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SA-PDPL-18 Regular security testing and assessment SBD-DEV-05 Secure Software Development Framework IM8-DSS.3 Secure Development Practices PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights 3(e)(i)(C) Sec. 3(e)(i)(C) (now 3(c)(i)(C)) Use secure software and hardware development for civil space systems URUGUAY-4 Security and Cross-Border VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 158 it maps to, and the evidence behind each claim, over MCP and REST.