6.5 Security
govstack-cfr-security2.0.0
#1 Enforce Transport Security (REQUIRED IMMUTABLE) (previously 5.12)
#2 Use Secure Configuration (REQUIRED IMMUTABLE) (previously 5.21)
#3 Include Support for Capturing Logging information (REQUIRED IMMUTABLE) (previously 5.10)
#4 Security testing is completed before solution is shared for use by others. This must include coverage of high-risk vulnerabilities as described in globally recognized standards (e.g. OWASP Top 10).
(REQUIRED IMMUTABLE)
#5 No sensitive data such as keys, certificates, or passwords is stored in code repositories or documentation.
(REQUIRED IMMUTABLE)
#6 Include Clearly-Defined Key Rotation Policies (RECOMMENDED EXTENSIBLE) (previously 5.16)
#7 Use I/O Sanitization (RECOMMENDED EXTENSIBLE) (previously 5.25)
#8 Only up-to-date and industry-accepted cryptographic algorithms MUST be used for data protection.
(RECOMMENDED IMMUTABLE)
#9 Enforce Access Control and Authentication (REQUIRED EXTENSIBLE)
#10 Implement Secure API Gateways (RECOMMENDED EXTENSIBLE)
#11 Implement Continuous Vulnerability Scanning and Patching (RECOMMENDED EXTENSIBLE)
#12 Ensure Isolation and Containment (RECOMMENDED EXTENSIBLE)
#13 Logging and Monitoring Security Events (REQUIRED EXTENSIBLE)
#14 Adopt Secure Coding and Review Practices (RECOMMENDED EXTENSIBLE)
#15 Disaster Recovery and Incident Response (RECOMMENDED EXTENSIBLE)
#16 Compliance and Audit Readiness (RECOMMENDED IMMUTABLE)
Last updated
Was this helpful?