A.8.26 Application Security Requirements
Control Objective
Information security requirements shall be identified, specified and approved when developing or acquiring applications.
Policy Statement
anDREa mandates that comprehensive information security requirements are systematically defined, formalized, and approved at the inception of any software initiative—whether developing proprietary capabilities for the myDRE platform or acquiring external third-party applications. This guarantees that security is treated as a fundamental baseline rather than a retrospective adjustment.
1. Unified Security Requirements Gathering
During the initial scoping and planning phases of both software engineering and procurement, technical and compliance teams must identify core security requirements alongside traditional functional attributes. This analysis encompasses:
- CIA Triad Controls: Core parameters dictating the necessary levels of confidentiality, integrity, and availability for the data lifecycle.
- Access & Identity Governance: Rules specifying required authentication factors, user provisioning mechanisms, and Role-Based Access Control (RBAC) granularities.
- Cryptographic Baselines: Encryption mandates covering both transit channels and storage-at-rest tiers.
- Audit & Monitoring Capabilities: Specific system, administrative, and error logging specifications required to expose anomalous behavior or fulfill compliance baselines.
- Regulatory Alignment: Verification of full compliance with relevant statutory frameworks, contract rules, and localized privacy regulations (e.g., GDPR, NIS 2).
Formalization Mechanism: The collected parameters must be explicitly analyzed, recorded, and formally approved within a dedicated SIA Instructions before implementation or procurement can proceed.
2. Software Development (In-House Engineering)
To operationalize Security-by-Design across proprietary platform developments, generalized SIA requirements are enhanced through a structured engineering lifecycle:
-
Architectural Alignment: Development pipelines must explicitly integrate the controls and principles established across our core engineering policies:
-
Developer Secure Coding Checklist: Software engineers must actively consult and sign off on the Patching Performance during individual code construction and compilation phases.
Post-Deployment Continuous Security & Lifecycle Care
Once software is introduced into the production myDRE environment, ongoing operational security is preserved through five interconnected layers:
- Logging & Event Monitoring: Continuous integration with central SIEM/log engines to capture systemic anomalies or security events (see A.08.15 - Logging and A.08.16 - Monitoring activities).
- Vulnerability Management: Proactive, automated code and dependency scanning to expose hidden flaws (see A.08.08 - Management of technical vulnerabilities).
- Security Patch Management: Immediate application of software upgrades and security revisions in strict accordance with the company’s Patch Management SLA.
- Incident Response Readiness: Full alignment with formalized technical playbooks to rapidly contain or mitigate application exploits (see A.05.25 - Assessment and decision on information security events).
- Independent Security Audits: Deployed features or application revisions are programmatically added to the scope of the next scheduled third-party Penetration Testing cycle.
3. Application Acquisition (Third-Party Procurement)
When anDREa acquires external applications, utilities, or SaaS subscriptions, information security compliance is evaluated through our standardized vendor onboarding framework. The acquisition process must strictly conform to the security controls, review cycles, and legal requirements detailed within the following policies:
- A.05.19 - Information security in supplier relationships
- A.05.20 - Addressing information security within supplier agreements
- A.05.21 - Managing information security in the information and communication technology (ICT) supply chain
- A.05.22 - Monitoring, review and change management of supplier services
- A.05.23 - Information security for use of cloud services