cds-snc / saas-procurement

Repo for the Saas Procurement app
MIT License
1 stars 0 forks source link

Security & Privacy Requirements #329

Open cgye opened 9 months ago

cgye commented 9 months ago

Identify non-functional Security & Privacy Requirements which are required for compliance with:

Per Secure SDLC, security & privacy requirements should be determined early in the process. Section 3.1 Mandatory Requirements and Section 3.2 Recommended Requirements of this document describes the Security & Privacy Requirements which must/should be considered.

dinophile commented 9 months ago

SaaS procurement feature is confirmed to need PBMM controls. As per Jenn S.

Training form feature will require PBMM eventually, so we will evaluate it as such from the beginning.

cgye commented 8 months ago

The following are currently executed, in scope, Security & Privacy requirements per Section 3.1 Mandatory Requirements of Secure Software Development Lifecycle:

The following are new, where the scope is up for discussion, Security & Privacy requirements per Section 3.1 Mandatory Requirements of Secure Software Development Lifecycle: