Security integration into the development methodology
Security activities must be embedded into the organization’s development methodology, cadence, artifacts, roles, and decision points.
Example: Reassess Security integration into the development methodology using current risk, accountable roles, updated artifacts, and evidence appropriate to the development method.
Counterexample: Have the security team address Security integration into the development methodology only at the final release review. | Reuse the previous approval even though requirements or architecture affecting Security integration into the development methodology changed. | Remove product-team accountability and assign all decisions about Security integration into the development methodology to a separate security function.
Limitations: Do not treat “secure SDLC” as a separate sequence that begins after functional development is complete.