PDP-11 SDLC – Security Reviews

Estimated reading: 2 minutes 1976 views

What is PDP-11 SDLC – Security Reviews Control?

PDP-11 SDLC – Security Reviews talks about each change undergoing a security review. This needs to be formally called out in the policy, and a step-by-step procedure for performing this review must be documented.

Available tools in the marketplace

 Tools
No tool recommendation is made for this section

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

  • N/A: no template for this section (see Security Review evidence below)

Control implementation

To implement this control,

You need to define and document a procedure for step-by-step guidance to perform security reviews. Implement a formal and repeatable process to perform security reviews as part of the change management workflow.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide evidence that the security review requirement is in the policy or workflow.
  2. Provide an example of a security review for one code change.

Evidence example

For the suggested action, an example is provided below:

  1. Provide evidence that the security review requirement is in the policy or workflow.
    The following screenshot shows the security review procedures available on TrustCloud’s internal sharing site.
    PDP 11 SDLC Security Reviews 01
  2. Provide an example of a security review for one code change.
    The following screenshot shows an example of a code review on a ticket in TrustCloud.
    PDP 11 SDLC Security Reviews 02

Join the conversation

You might also be interested in

Documentation Templates

Documentation Templates are documents that provide a content outline to meet certain documentation needs....

Data Backup Plan Template

The Data Backup Plan template helps you document in detail the data backup needs...

HR-13 Employee Handbook/Code of Conduct

HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It...

AUTH-1 Single Sign On (SSO)

Single Sign On (SSO) Control is a best practice recommendation for critical systems....

Security Incident Report Template

The Security Incident Report template helps you document the steps used to assess and...

BIZOPS-6 Disaster Recovery Testing

BIZOPS-6 Disaster Recovery Testing control refers to the exercise of identifying the critical systems...

PDP-10 SDLC – Separation of environments

PDP-10 SDLC Separation of Environments is important to maintain separate environments to develop, test,...

Privacy Committee Charter Template

Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's...
ON THIS PAGE
SHARE THIS PAGE

SUBSCRIBE
FlightSchool
OR