02 — Capability · BC-1270.30
Product Security Engineering
Build security into the product from design through release — threat models, secure coding, testing and dependency hygiene — so vulnerabilities are prevented rather than patched after a report.
- Application Security
- Secure SDLC
- AppSec
In scope
- Threat modeling and security design review
- Static, dynamic and dependency scanning in the pipeline
- Penetration testing of the product
- Security training for product engineers
Out of scope
- Enterprise network and endpoint security (see BC-760)
- Platform hardening and secrets infrastructure (see BC-1210)
Realized by · 0
- No product in the catalog yet.
Used in · 1
Build it · 1
Decomposes into · 4
- BC-1270.30.10Threat Modeling & Design ReviewExamine new features for what could go wrong before they are built, and record the mitigations chosen.
- BC-1270.30.20Security Testing in the PipelineRun code, dependency and runtime security checks on every change with thresholds that block a release.
- BC-1270.30.30Penetration TestingCommission and act on regular independent testing of the product and share sanitized results with customers.
- BC-1270.30.40Secure Development EnablementTrain engineers, embed security champions in teams and supply libraries that make the safe path the easy one.