PCI Software Security Framework, Secure SLC Standard
The PCI Secure SLC Standard is one of two standards in the PCI Software Security Framework, published by the PCI Security Standards Council; the other governs the software itself. Secure SLC instead addresses a software vendor's secure development lifecycle. This page indexes its requirement groups against the themes below.
| Requirement group | Themes |
|---|---|
| Governance and security responsibility | T1 Documented and applied lifecycle T9 Segregation of duties and least privilege T15 Accountability for assisted development |
| Secure software engineering | T2 Requirements and security criteria before implementation T3 Design and analysis before implementation T4 Secure coding and code quality T5 Independent review before a change is accepted |
| Security testing | T6 Automated security verification T7 Testing and acceptance |
| Change management and software integrity | T8 Change control and traceability T12 Build and release integrity |
| Vulnerability management and stakeholder communication | T13 Vulnerability handling and disclosure T14 Security updates and supported versions |