Secure by Design: A Guide for Manufacturers (CISA)
Secure by design tactics: development roadmap practices – Secure by Design: A Guide for Manufacturers (CISA)

Secure by Design: A Guide for Manufacturers (CISA) DT-6: Static and dynamic application security testing (SSDF PW.7.2, PW.8.2)

Run SAST on source code and DAST on application behaviour automatically in the development process to find error-prone practices from memory mismanagement to unsafe query construction, alongside unit and integration testing, and carry out root cause analysis on findings so they are addressed systematically.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Secure by design tactics: development roadmap practices – Secure by Design: A Guide for Manufacturers (CISA)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.