Context
vsms already has strong CI and release practices, but ISO/IEC 27001 readiness requires secure-development and vulnerability-management controls to be explicit, consistently enforced and evidenced.
Relevant control themes include secure development lifecycle, application security requirements, secure coding, security testing, technical vulnerability management, change management and supply-chain integrity.
Scope
Document and enforce the secure path from requirement/change through review, CI, artifact publication and deployment. Include dependency/advisory scanning, security exceptions, remediation targets, release provenance and third-party action/tool pinning.
Reuse existing supply-chain work such as #354 rather than creating a parallel provenance mechanism.
Acceptance
Context
vsms already has strong CI and release practices, but ISO/IEC 27001 readiness requires secure-development and vulnerability-management controls to be explicit, consistently enforced and evidenced.
Relevant control themes include secure development lifecycle, application security requirements, secure coding, security testing, technical vulnerability management, change management and supply-chain integrity.
Scope
Document and enforce the secure path from requirement/change through review, CI, artifact publication and deployment. Include dependency/advisory scanning, security exceptions, remediation targets, release provenance and third-party action/tool pinning.
Reuse existing supply-chain work such as #354 rather than creating a parallel provenance mechanism.
Acceptance