PO.3.1_po31
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
Define criteria for software security checks and track throughout the SDLC.
Separate and protect each environment involved in software development.
Organizational cybersecurity policy is established, communicated, and enforced
Identities and credentials for authorized users, services, and hardware are managed by the organization
Identities are proofed and bound to credentials based on the context of interactions
Users, services, and hardware are authenticated
Identity assertions are protected, conveyed, and verified