Skip to main content

PCI Software Security Framework, Secure SLC Standard

The PCI Secure SLC Standard is one of two standards in the PCI Software Security Framework, published by the PCI Security Standards Council; the other governs the software itself. Secure SLC instead addresses a software vendor's secure development lifecycle. This page indexes its requirement groups against the themes below.

Requirement groupThemes
Governance and security responsibilityT1 Documented and applied lifecycle
T9 Segregation of duties and least privilege
T15 Accountability for assisted development
Secure software engineeringT2 Requirements and security criteria before implementation
T3 Design and analysis before implementation
T4 Secure coding and code quality
T5 Independent review before a change is accepted
Security testingT6 Automated security verification
T7 Testing and acceptance
Change management and software integrityT8 Change control and traceability
T12 Build and release integrity
Vulnerability management and stakeholder communicationT13 Vulnerability handling and disclosure
T14 Security updates and supported versions