Sekit CSF · Familia
Application Security
30 controles en 10 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0136API securitysin mapeos aúnSecurity requirements for all application programming interfaces are formally defined and documentedRCF-0130CI/CD hardeningsin mapeos aúnSecurity controls in the software build and deployment pipeline are formally defined and requiredRCF-0139Container securitysin mapeos aúnSecurity standards for building and running containerised applications are formally definedRCF-0127Dependency/SBOM managementsin mapeos aúnThe company formally tracks all software components and third-party libraries used in its applicationsRCF-0142DevSecOps governancesin mapeos aúnAccountability for security within development and operations teams is formally definedRCF-0133IaC scanningsin mapeos aúnSecurity scanning of infrastructure-as-code templates is formally required before deploymentRCF-0124SAST/DASTsin mapeos aúnFormal policy requires automated security testing of application code and running applicationsRCF-0121Secure code reviewsin mapeos aúnSecurity review of code is formally required before it is released to productionRCF-0115Secure SDLC policysin mapeos aúnSecurity requirements are formally integrated into the software development lifecycle from planning to releaseRCF-0118Threat modelingsin mapeos aúnThe company formally identifies and documents potential threats to applications before development begins
Proceso
RCF-0137API securitysin mapeos aúnAPIs are consistently designed, tested and monitored to meet security requirementsRCF-0131CI/CD hardeningsin mapeos aúnPipeline security controls are consistently applied and reviewed for every build and deploymentRCF-0140Container securitysin mapeos aúnContainer images and configurations are consistently reviewed against security standardsRCF-0128Dependency/SBOM managementsin mapeos aúnSoftware bills of materials are consistently maintained and reviewed for known vulnerabilitiesRCF-0143DevSecOps governancesin mapeos aúnSecurity is consistently embedded into development team practices and sprint cyclesRCF-0134IaC scanningsin mapeos aúnInfrastructure templates are consistently scanned for misconfigurations before being appliedRCF-0125SAST/DASTsin mapeos aúnStatic and dynamic security tests are consistently run as part of the build and release processRCF-0122Secure code reviewsin mapeos aúnCode reviews consistently include security checks performed by trained developersRCF-0116Secure SDLC policysin mapeos aúnSecurity activities are consistently applied at each stage of the development processRCF-0119Threat modelingsin mapeos aúnThreat modeling is consistently conducted for new features and significant changes
Técnica
RCF-0138API securitysin mapeos aúnTechnical controls enforce authentication, authorisation and rate limiting on all API endpointsRCF-0132CI/CD hardeningsin mapeos aúnTechnical controls protect the build pipeline from tampering and enforce security gates at each stageRCF-0141Container securitysin mapeos aúnTechnical tools scan container images and enforce runtime security policies automaticallyRCF-0129Dependency/SBOM managementsin mapeos aúnTechnical tools automatically identify vulnerable dependencies and alert or block affected buildsRCF-0144DevSecOps governancesin mapeos aúnTechnical dashboards provide visibility of security posture across all development pipelinesRCF-0135IaC scanningsin mapeos aúnAutomated tools scan infrastructure code for security issues and block deployment of non-compliant templatesRCF-0126SAST/DASTsin mapeos aúnAutomated SAST and DAST tools integrate into the pipeline and block releases with critical findingsRCF-0123Secure code reviewsin mapeos aúnAutomated tools scan code for security vulnerabilities as part of the development workflowRCF-0117Secure SDLC policysin mapeos aúnTechnical gates enforce security checks before code can progress through the development pipelineRCF-0120Threat modelingsin mapeos aúnTechnical tools support structured threat modeling and track identified risks to resolution
Pregúntale a Sekura: «¿Qué evidencia demuestra Application Security?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.