SA-10(7)_security-and-privacy-representatives
Require [organization-defined] to be included in the [organization-defined].
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Require [organization-defined] to be included in the [organization-defined].
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
Require an independent agent satisfying [organization-defined] to verify the correct implementation of the developer security and privacy assessmen...
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
Require the developer of the system, system component, or system service to perform attack surface reviews.
Acquisition Strategies / Tools / Methods
Penetration Testing / Analysis of Elements, Processes, and Actors
Inter-organizational Agreements
Critical Information System Components