Mechanisms exist to require software developers to provide information describing the functional properties of the security controls to be utilized within Technology Assets, Applications and/or Services (TAAS) in sufficient detail to permit analysis and testing of the controls.
Does the organization require software developers to provide information describing the functional properties of the security controls to be utilized within Technology Assets, Applications and/or Services (TAAS) in sufficient detail to permit analysis and testing of the controls?
- wordsmithed control