Security requirements are formally integrated into the software development lifecycle from planning to release
Sekit's Secure SDLC policy, one of the topic-specific policies A.5.1 expects, builds security requirements into every stage of development, from design through release, for in-house and outsourced work alike.
This policy control builds security requirements into each stage of software development, from design through release, supporting A.5.8's wider requirement to embed security into every project, software or not.
This policy facet builds security requirements into each development stage, from design through release, for in-house and outsourced work, matching A.8.25's core lifecycle requirement.