SA-11(1)_static-code-analysis
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
Test malicious code protection mechanisms [organization-defined] by introducing known benign code into the system;
Help identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation.
Testing for Broken Object Level Authorization (BOLA)