Sekit CSF · Familia
Application Security
30 controles en 10 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0136API security5 mapeosSecurity requirements for all application programming interfaces are formally defined and documentedRCF-0130CI/CD hardening6 mapeosSecurity controls in the software build and deployment pipeline are formally defined and requiredRCF-0139Container security7 mapeosSecurity standards for building and running containerised applications are formally definedRCF-0127Dependency/SBOM management8 mapeosThe company formally tracks all software components and third-party libraries used in its applicationsRCF-0142DevSecOps governance5 mapeosAccountability for security within development and operations teams is formally definedRCF-0133IaC scanning6 mapeosSecurity scanning of infrastructure-as-code templates is formally required before deploymentRCF-0124SAST/DAST6 mapeosFormal policy requires automated security testing of application code and running applicationsRCF-0121Secure code review5 mapeosSecurity review of code is formally required before it is released to productionRCF-0115Secure SDLC policy7 mapeosSecurity requirements are formally integrated into the software development lifecycle from planning to releaseRCF-0118Threat modeling7 mapeosThe company formally identifies and documents potential threats to applications before development begins
Proceso
RCF-0137API security6 mapeosAPIs are consistently designed, tested and monitored to meet security requirementsRCF-0131CI/CD hardening5 mapeosPipeline security controls are consistently applied and reviewed for every build and deploymentRCF-0140Container security8 mapeosContainer images and configurations are consistently reviewed against security standardsRCF-0128Dependency/SBOM management7 mapeosSoftware bills of materials are consistently maintained and reviewed for known vulnerabilitiesRCF-0143DevSecOps governance5 mapeosSecurity is consistently embedded into development team practices and sprint cyclesRCF-0134IaC scanning5 mapeosInfrastructure templates are consistently scanned for misconfigurations before being appliedRCF-0125SAST/DAST6 mapeosStatic and dynamic security tests are consistently run as part of the build and release processRCF-0122Secure code review4 mapeosCode reviews consistently include security checks performed by trained developersRCF-0116Secure SDLC policy7 mapeosSecurity activities are consistently applied at each stage of the development processRCF-0119Threat modeling6 mapeosThreat modeling is consistently conducted for new features and significant changes
Técnica
RCF-0138API security6 mapeosTechnical controls enforce authentication, authorisation and rate limiting on all API endpointsRCF-0132CI/CD hardening6 mapeosTechnical controls protect the build pipeline from tampering and enforce security gates at each stageRCF-0141Container security9 mapeosTechnical tools scan container images and enforce runtime security policies automaticallyRCF-0129Dependency/SBOM management6 mapeosTechnical tools automatically identify vulnerable dependencies and alert or block affected buildsRCF-0144DevSecOps governance5 mapeosTechnical dashboards provide visibility of security posture across all development pipelinesRCF-0135IaC scanning5 mapeosAutomated tools scan infrastructure code for security issues and block deployment of non-compliant templatesRCF-0126SAST/DAST5 mapeosAutomated SAST and DAST tools integrate into the pipeline and block releases with critical findingsRCF-0123Secure code review4 mapeosAutomated tools scan code for security vulnerabilities as part of the development workflowRCF-0117Secure SDLC policy6 mapeosTechnical gates enforce security checks before code can progress through the development pipelineRCF-0120Threat modeling5 mapeosTechnical tools support structured threat modeling and track identified risks to resolution
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Application Security?»
También vía MCP, gratis con cuenta