Skip to main content

💼 6.2.3 Bespoke and custom software is reviewed prior to being released into production or to customers, to identify and correct potential coding vulnerabilities.

  • ID: /frameworks/pci-dss-v4.0.1/06/02/03

Description

As follows:

  • Code reviews ensure code is developed according to secure coding guidelines.
  • Code reviews look for both existing and emerging software vulnerabilities.
  • Appropriate corrections are implemented prior to release.

Similar

  • Sections
    • /frameworks/pci-dss-v4.0/06/02/03
    • /frameworks/aws-fsbp-v1.0.0/ecr/01

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [ECR.1] ECR private repositories should have image scanning configured11no data
💼 PCI DSS v4.0 → 💼 6.2.3 Bespoke and custom software is reviewed prior to being released into production or to customers, to identify and correct potential coding vulnerabilities.11no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v4.0 → 💼 6.2.3 Bespoke and custom software is reviewed prior to being released into production or to customers, to identify and correct potential coding vulnerabilities.11no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 6.2.3.1 If manual code reviews are performed for bespoke and custom software prior to release to production, code changes are reviewed by individuals other than the originating code author, and who are knowledgeable about code-review techniques and secure coding practices reviewed and approved by management prior to release.1no data

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ AWS ECR Repository Manual Scanning is enabled🟢1🟢 x6no data