Frameworks / OWASP DevSecOps Maturity Model (DSOMM) / DSOMM-4 OWASP DevSecOps Maturity Model (DSOMM)
Test and Verification
OWASP DevSecOps Maturity Model (DSOMM) DSOMM-4: Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing Per OWASP DSOMM Test and Verification dimension: implement comprehensive security testing. Requirements include (a) integrate Static Application Security Testing (SAST) in CI/CD with developer feedback + tuning + (b) operate Dynamic Application Security Testing (DAST) against running applications + APIs + (c) implement Interactive Application Security Testing (IAST) where appropriate + (d) operate Software Composition Analysis (SCA) for dependency vulnerabilities + license issues + (e) implement API security testing covering OWASP API Top 10 + business logic + (f) operate fuzz testing for protocol + data parsing + (g) conduct penetration testing + bug bounty + red team activities + (h) maintain security test cases in CI pipelines + with regression coverage.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 189 controls across 122 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CPG-1.A Changing Default Passwords CPG-1.C Unique Credentials CPG-4.C Basic Cybersecurity Training CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements Part11.300 Controls for identification codes and passwords (21 CFR §11.300) Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 27011-5.6 Supplier relationships and telecom supply chain 27011-8.1 User Endpoint Devices 27400-6.1 Secure Device Design 27400-6.3 Secure Update Mechanism ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NDPA-1 Applicability, Scope, and Carve-Outs NDPA-6 Reasonable Security Practices and Incident Response NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust USMCADIGITAL-2 Personal Information Protection and Consumer Protection USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records AMLCTF-35 Identity Verification Standard APPI-A31 Provision of Personally Referable Information AS9100D-8.4 Control of Externally Provided Processes, Products, Services Clause 3 Suppliers and service providers ACQ.4 Supplier Monitoring BH-PDPL-18 Regular security testing and assessment DSO-3 Data Access Management LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour CJIS-19 Supply Chain Risk Management CAT-IRP-4 Organizational characteristics FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) GAMP5-2nd-Edition-AI-Cloud-Agile-CSA 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA) GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain 62351-8 Role-based access control (RBAC) IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe A.1 Point-of-Care Testing Additional Requirements 23837-1.7.3 Authentication and classical post-processing 27010-15.1 Incident Management INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NHPA-6 Reasonable Data Security and Breach Response NJDPA-6 Reasonable Data Security and Incident Response NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security OECDMNE-5 Environment, Climate, and Biodiversity OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OMANCS-3 Identity and Access Management, Authentication, Privileged Access OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling AUPRV-4 APP 10-11 Quality, Security of Personal Information RUSPD-2 Lawful Basis, Consent, Notice PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 TEFCAREC-1 Common Agreement Conformance and Onboarding ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 189 it maps to, and the evidence behind each claim, over MCP and REST.