AIS: Application & Interface Security
Controls
AIS-01: Application and Interface Security Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at least annually.
AIS-02: Application Security Baseline Requirements
Establish, document and maintain baseline requirements for securing different applications.
AIS-03: Application Security Metrics
Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
AIS-04: Secure Application Design and Development
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-05: Automated Application Security Testing
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
AIS-06: Automated Secure Application Deployment
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
AIS-07: Application Vulnerability Remediation
Define and implement a process to remediate application security vulnerabilities, automating remediation when possible.