02 — Capability · BC-760.50
Application & Data Security
Build security into the software the enterprise writes and buys, and protect the data it holds through encryption, key control and controls on where data may go.
- AppSec
- Data Protection
- Secure Development
In scope
- Secure development practices and training
- Application security testing before and after release
- Encryption and key management
- Data loss prevention and monitoring
Out of scope
- Functional and performance testing (see BC-720)
- Data classification policy itself (see BC-750)
Realized by · 3
Used in · 2
Build it · 3
Decomposes into · 4
- BC-760.50.10Secure Development PracticesEmbed threat modeling, secure coding standards and dependency checks into the delivery pipeline so most flaws never reach a tester.
- BC-760.50.20Application Security TestingTest code and running applications for exploitable weaknesses, including penetration tests on the systems that matter most.
- BC-760.50.30Encryption & Key ManagementEncrypt data in transit and at rest where its classification requires, and manage the keys and certificates with a lifecycle that never expires in production unnoticed.
- BC-760.50.40Data Loss PreventionDetect and block sensitive data leaving through email, storage, endpoints and cloud services in ways policy does not allow.