CSC V7 control 18.4 – Only Use Up-to-date And Trusted Third-Party Components Overview CSC V7 control 18.4 recommends that organisations “Only use up-to-date and trusted third-party components for the software developed by...
CSC V7 control 18.5 – Use Only Standardized and Extensively Reviewed Encryption Algorithms Overview CSC V7 control 18.5 recommends that organisations “Use only standardized and extensively reviewed encryption algorithms. Note CSC V7 places...
CSC V7 control 18.6 – Ensure Software Development Personnel are Trained in Secure Coding Overview CSC V7 control 18.6 recommends that organisations “Ensure that all software development personnel receive training in writing secure code...
CSC V7 control 18.7 – Apply Static and Dynamic Code Analysis Tools Overview CSC V7 control 18.7 recommends that organisations “Apply static and dynamic analysis tools to verify that secure coding practices...
CSC V7 control 18.8 – Establish a Process to Accept and Address Reports of Software Vulnerabilities Overview CSC V7 control 18.8 recommends that organisations “Establish a process to accept and address reports of software vulnerabilities, including...
CSC V7 control 18.9 – Separate Production and Non-Production Systems Overview CSC V7 control 18.9 recommends that organisations “Maintain separate environments for production and nonproduction systems. Developers should not have...
CSC V7 control 18.10 – Deploy Web Application Firewalls (WAFs) Overview CSC V7 control 18.10 recommends that organisations “Protect web applications by deploying web application firewalls (WAFs) that inspect all...
CSC V7 control 18.11 – Use Standard Hardening Configuration Templates for Databases Overview CSC V7 control 18.11 recommends that organisations “For applications that rely on a database, use standard hardening configuration templates....
CSC V7 control 19 – Incident Response and Management Overview CSC V7 control 19 recommends that organisations “ Note CSC V7 places this control in the category of “Incident...
CSC V7 control 19.1 – Document Incident Response Procedures Overview CSC V7 control 19.1 recommends that organisations “Ensure that there are written incident response plans that defines roles of...