NIST SP 800-218 218-PW.1.1: Design Software to Meet Security Requirements
Design software so that it meets security requirements and mitigates known risks from the start. Use threat modelling to identify how an attacker could abuse the system and feed mitigations back into the design.
What else in your programme already covers this
This control maps to 51 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-SA-17 Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's
NIST800-SA-8 Security and privacy engineering principles
SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing
SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing
NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
6.2.1 Bespoke and custom software are developed securely, as follows: • Based on industry standards and/or best practices for secure development. • In accordance with PCI DSS (for example, secure authentication and logging). • Incorporating
You are reading one control. How much of NIST SP 800-218 have you already done?
NIST SP 800-218 218-PW.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-218 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 30 of 42 NIST SP 800-218 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.