PCI DSS 4.0 6.2.3: 6.2.3 Code review before release
Before bespoke and custom software is released to production or to customers, it must be reviewed to find and fix possible coding vulnerabilities, such that: reviews confirm the code follows secure coding guidelines; reviews look for vulnerabilities that are already known as well as newly emerging ones; and suitable fixes are made before release. It applies to all entities. Applicability: the review requirement covers every piece of custom and bespoke software, whether public facing or internal, within the development lifecycle; public-facing web applications additionally fall under Requirement 6.4; reviews may be manual, automated or both. Objective under the customized approach: coding vulnerabilities in bespoke and custom software cannot be used to exploit it.
This control maps to 44 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 6.2.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.