Security controls in the software build and deployment pipeline are formally defined and required
Sekit's CI/CD hardening policy is part of A.5.1's topic-specific policy layer: it sets written security requirements for the build and deployment pipeline, treating it as a production system in its own right.
This policy facet sets written security requirements for the build and deployment pipeline itself, treating it as a production system A.8.25 must protect.
Written security requirements for the build and deployment pipeline treat it as a production system, extending A.8.9's configuration discipline to the pipeline itself.