NIST SP 800-218 (SSDF) v1.1
NIST SP 800-218, the Secure Software Development Framework (SSDF), is a set of fundamental secure-development practices published by NIST for producers of software. Version 1.1 groups those practices under four headings: preparing the organization, protecting the software, producing well-secured software, and responding to vulnerabilities. This page indexes each group against the themes below.
| Requirement group | Themes |
|---|---|
| PO Prepare the Organization | T1 Documented and applied lifecycle T9 Segregation of duties and least privilege T15 Accountability for assisted development |
| PS Protect the Software | T8 Change control and traceability T12 Build and release integrity |
| PW Produce Well-Secured Software | T2 Requirements and security criteria before implementation T3 Design and analysis before implementation T4 Secure coding and code quality T5 Independent review before a change is accepted T6 Automated security verification T7 Testing and acceptance |
| RV Respond to Vulnerabilities | T13 Vulnerability handling and disclosure T14 Security updates and supported versions |