16.11—Leverage Vetted Modules or Services for Application Security Components
IG2
IG3
Software
Protect
>Control Description
Leverage vetted modules or services for application security components, such as identity management, encryption, auditing, and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern operating systems provide effective mechanisms for identification, authentication, and authorization and make those mechanisms available to applications. Use only standardized, currently accepted, and extensively reviewed encryption algorithms. Operating systems also provide mechanisms to create and maintain secure audit logs.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.