Secure SDLC (SSDLC)
Document control
Supply Chain Security
Development is performed by a third-party firm: their developers are GitHub collaborators with no AWS access. They can only propose changes; nothing reaches production without S.E.T-team approval. This section defines how a code change travels safely from a developer's laptop to production, and the controls at each stage.
Secure SDLC — Policies
19 items