| 5.20 Addressing information security within supplier agreements | T11 Third-party components and supply chain T13 Vulnerability handling and disclosure |
| 8.8 Management of technical vulnerabilities | T6 Automated security verification T13 Vulnerability handling and disclosure T14 Security updates and supported versions |
| 8.25 Secure development life cycle | T1 Documented and applied lifecycle T2 Requirements and security criteria before implementation T3 Design and analysis before implementation |
| 8.26 Application security requirements | T2 Requirements and security criteria before implementation |
| 8.27 Secure system architecture and engineering principles | T3 Design and analysis before implementation |
| 8.28 Secure coding | T4 Secure coding and code quality T5 Independent review before a change is accepted |
| 8.29 Security testing in development and acceptance | T6 Automated security verification T7 Testing and acceptance |
| 8.30 Outsourced development | T5 Independent review before a change is accepted T11 Third-party components and supply chain T15 Accountability for assisted development |
| 8.31 Separation of development, test and production environments | T10 Separation of development, verification and released code |
| 8.32 Change management | T8 Change control and traceability |
| 8.33 Test information | T7 Testing and acceptance |