PDP-13 Secure coding practice

Estimated reading: 1 minute 1588 views

What is PDP-13 Secure Coding Practice Control?

The PDP-13 Secure Coding Practice Control talks about each organization having a coding practice to securely deploy changes to production. This practice must be documented and made available to all employees. This can be documented within the change policy or as a standalone document, and there is no formal or specific requirement for the documentation.

Available tools in the marketplace

 Tools
No tool recommendation is made for this section

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

Control implementation

To implement this control,

You need to define and document a procedure for step-by-step guidance for secure coding.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide the most up-to-date secure coding plan.

Evidence example

For the suggested action, an example is provided below:

  1. Provide the most up-to-date secure coding plan.
    The following screenshot shows the agile process documented within the development process in TrustCloud.
    PDP 13 Secure coding practice 01

Join the conversation

ON THIS PAGE
SHARE THIS PAGE

SUBSCRIBE
FlightSchool
OR