Companion-course connectionPCI Software Security Framework
The PCI Software Security Framework establishes security expectations for payment software and its lifecycle, including secure design, development, testing, release, vulnerability management, and ongoing maintenance.
Open article →Companion-course connectionSecure Software Deployment
Secure software deployment moves approved software into an environment using controlled identities, verified artifacts, protected configuration, rollback capability, and observable change.
Open article →Companion-course connectionSecure Software Requirements
Secure software requirements translate risk, policy, misuse cases, compliance, and design objectives into testable conditions for a system and its development process.
Open article →Companion-course connectionSoftware Supply Chain Security
Software supply chain security protects source, dependencies, build systems, artifacts, distribution, updates, and the people and services that influence delivered software.
Open article →Companion-course connectionApplication Security Governance
Application security governance connects engineering work to risk ownership, secure design expectations, delivery controls, exceptions, evidence, and operational accountability.
Open article →Companion-course connectionCloud Workload Protection
Cloud workload protection applies preventive and detective controls to virtual machines, containers, serverless functions, and managed compute environments.
Open article →Companion-course connectionNetwork Architecture Validation
Network architecture validation proves that a design and its implementation satisfy documented business, technical, security, compliance, availability, and operational requirements.
Open article →Companion-course connectionPCI Penetration Test Evidence
PCI penetration test evidence shows that qualified testers evaluated relevant internal and external attack paths, segmentation, applications, network layers, scope assumptions, exploitable findings, and remediation.
Open article →Companion-course connectionProject Risk Statements
Project risk statements describe an uncertain event or condition, its cause or context, and the potential effect on one or more objectives.
Open article →Companion-course connectionRegulatory Incident Reporting
Regulatory incident reporting identifies applicable notification duties, responsible authorities, required content, decision evidence, and deadlines for a specific organization and event.
Open article →Companion-course connectionSecurity Procurement and Contracts
Security procurement integrates risk, architecture, privacy, resilience, assurance, and lifecycle requirements into sourcing and contract decisions.
Open article →Companion-course connectionSecurity Requirements Baseline
A security requirements baseline is the approved set of security requirements and assumptions against which the system is designed, built, verified, and changed.
Open article →