Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-6-1
Cybersecurity Requirements Must Be Included In Project And Asset (information/ Technology) Change
Management Methodology And Procedures To Identify And Manage Cybersecurity Risks As Part Of Project
Management Lifecycle. The Cybersecurity Requirements Must Be A Key Part Of The Overall Requirements
Of Technology Projects.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-6-2
- The cybersecurity requirements in project and assets (information/technology) change management must include at least the following:
- Vulnerability assessment and remediation.
- Conducting a configurations’ review, secure configuration and hardening and patching before changes or going live for technology projects.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-6-3
- The cybersecurity requirements related to software and application development projects must include at least the following:
- Using secure coding standards.
- Using trusted and licensed sources for software development tools and libraries.
- Conducting compliance test for software against the defined organizational cybersecurity requirements.
- Secure integration between software components.
- Conducting a configurations’ review, secure configuration and hardening and patching before going live for software products.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-6-4
The Cybersecurity Requirements In Project Management Must Be Reviewed Periodically.