Frameworks / OWASP SAMM / OWASPSAMM-2 OWASP SAMM OWASPSAMM-2: Design: Threat Assessment, Security Requirements, Security Architecture Per OWASP SAMM v2 Design business function: secure design practices. Security Practices: (1) Threat Assessment including application threat modelling + risk assessment + (2) Security Requirements including functional security requirements + supplier security requirements + (3) Security Architecture including reference architecture + secure design patterns + technology controls. Requirements include (a) conduct threat modelling at design phase + revise on significant change + (b) maintain documented security requirements per application + (c) maintain supplier + third-party security requirements + (d) define + maintain reference security architecture + secure design patterns + (e) provide technology controls + secure libraries + frameworks + (f) integrate design-time security activities into SDLC.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 299 controls across 92 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-06 Asset inventory and ownership ISO27043-08 Information classification and labeling ISO27043-10 Media management and disposal ISO27043-11 Access control policy and enforcement ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-07 Acceptable use of assets ISO21434-08 Information classification and labeling ISO21434-09 Asset handling procedures ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-15 Security categorization ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls 27010-10.1 Cryptographic Protection 27010-8.1 Membership Onboarding 27010-8.2 Membership Termination 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources QRCM-1.1 Cryptographic Asset Inventory QRCM-1.2 Quantum-Vulnerable Identification QRCM-1.3 Data Classification for Migration QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ISMSP-SYS-02 Encryption Implementation API1164-02 Risk Management Framework API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management ASD37-17 TLS encryption between email servers (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) IEC62443-02 System security categorization IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing ISO27019-02 System security categorization ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PTESPHASE-1 Pre-Engagement Interactions and Scoping PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling IM8-CLD.2 Cloud Security Controls IM8-DAT.1 Data Classification IM8-SEC.2 Access Control APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion DSO-2 Data Security DSO-3 Data Access Management CJIS-8 Media Protection CJIS-9 System and Communications Protection UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management ISO-19650-1-5 Delivery team and task team concepts ISO-19650-2-5.7 Information model delivery 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements SA-PDPL-13 Encryption of personal data SA-PDPL-15 Access control for personal data AMLCTF-35 Identity Verification Standard CA-ITSG33-SC-01 Security Control Catalogue QMSR-820.45 Device labelling and packaging controls (§820.45) FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 60601-1.7.1 Equipment identification and marking ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights UKGAMBLE-4 Resilience and Incident Response ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMPDP-2 Consent and Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 299 it maps to, and the evidence behind each claim, over MCP and REST.