Requirement 6: Develop and maintain secure systems and software
Vulnerabilities in your own and third-party software must be found and fixed, and software developed securely.
Sub-requirements
6.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument secure-development and patch policy.
View defined requirements →6.2
Bespoke and custom software is developed securely
5 defined requirementsTrain developers, use a secure SDLC, and review code before release.
View defined requirements →6.3
Security vulnerabilities are identified and addressed
3 defined requirementsTrack vulnerabilities (incl. dependencies), rank by risk, and patch critical ones within one month.
View defined requirements →6.4
Public-facing web applications are protected against attacks
3 defined requirementsUse a WAF or regular automated/manual application reviews.
View defined requirements →6.5
Changes to all system components are managed securely
6 defined requirementsApply change control with documentation, testing, approval and rollback.
View defined requirements →Tips
- ›Add SAST and dependency scanning to CI to cover 6.2 and 6.3 automatically.
- ›A WAF is the simplest route to 6.4 for most teams.
Evidence to keep
- ✓Secure SDLC document
- ✓Scan results and patch records
- ✓Change-control tickets
- ✓WAF configuration
Example
Code is peer-reviewed, CI runs SAST and dependency scanning, criticals are patched within 30 days, and a WAF fronts public apps.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.Vulnerability and patch management policyUse for ISO 27001 A.8.8, A.8.19, A.8.32, SOC 2 Security, and PCI DSS requirements 6 and 11.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.
Open the control-to-policy map