UK NCSC Cyber Assessment Framework
Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework A4.b: A4.b Secure software development and support

The organisation maximises use of secure, supported software, whether built internally or bought (new in v4.0). Partially achieved: suppliers follow secure development practices and understand software composition and provenance to a degree; development, test and production environments and repositories are proportionately secure; testing covers functional and non-functional aspects with static and dynamic analysis; timely security updates arrive through secure channels; suppliers handle vulnerabilities and notify significant events; open-source software is assessed; and support is in place. Achieved: suppliers use an established framework (for example NIST SSDF or Microsoft SDL), fully understand composition including third-party components monitored for vulnerabilities, environments resist capable actors, development uses threat modelling, and software authenticity and integrity can be attested.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.