Security activities are consistently applied at each stage of the development process
The process facet runs the agreed security activities, requirements capture, code review, dependency checks, on every feature and release, not only the large ones.
This Sekit process control performs security activities like code review on every release, one of the checks this ISO control requires before a change reaches production.