{"version":"0.2.0","built_at":"2026-10-10T20:58:14.188Z","license":"CC BY 4.0 © Mike Reams","canonical":"https://catalog.mikereams.com","capability":{"id":"BC-1270.30","name":"Product Security Engineering","level":2,"parent_id":"BC-1270","l1_id":"BC-1270","industry":"software","macro_id":null,"path":["Trust & Compliance Assurance","Product Security Engineering"],"description":"Build security into the product from design through release — threat models, secure coding, testing and dependency hygiene — so vulnerabilities are prevented rather than patched after a report.","aliases":["Application Security","Secure SDLC","AppSec"],"in_scope":["Threat modeling and security design review","Static, dynamic and dependency scanning in the pipeline","Penetration testing of the product","Security training for product engineers"],"out_of_scope":["Enterprise network and endpoint security (see BC-760)","Platform hardening and secrets infrastructure (see BC-1210)"],"csdm_note":null,"status":"active","successor_id":null,"child_ids":["BC-1270.30.10","BC-1270.30.20","BC-1270.30.30","BC-1270.30.40"]},"crosswalk":{"realized_by":[],"used_in":[{"vs_id":"VS-100","vs":"Commit-to-Production","stage_id":"VS-100.20","stage":"Test & Secure","order":2,"via":null}],"patterns":[],"stacks":[],"books":[{"id":"BK-threat-modeling","title":"Threat Modeling","topic":"Security","via":null}]},"ancestors":[{"id":"BC-1270","name":"Trust & Compliance Assurance","level":1}],"children":[{"id":"BC-1270.30.10","name":"Threat Modeling & Design Review","level":3,"child_count":0},{"id":"BC-1270.30.20","name":"Security Testing in the Pipeline","level":3,"child_count":0},{"id":"BC-1270.30.30","name":"Penetration Testing","level":3,"child_count":0},{"id":"BC-1270.30.40","name":"Secure Development Enablement","level":3,"child_count":0}]}