• • • • • secured software. Secure coding practices: internal documents describing the process to ensure secure coding practices are followed during the development of the device. List the standard, guideline, security best practices that are referenced. Improve executable security: evidence showing compiler and build tools configuration, or internal documents describing the process to improve the executable security. Functional testing of security features: test document such as functional testing test case document or test tool report describing the test cases (purpose and steps of each test case), or internal document(s) describing the process to conduct functional testing. Developer and/or peer code review: Internal document or evidence of the tracking system used for tracking the code review feedback and remediation status of the findings. Static application security testing (SAST): test report describing the CLS Publication #2 | Page 45 of 49

Select target paragraph3