•
•
•
•
•
secured software.
Secure coding practices: internal
documents describing the process
to ensure secure coding practices
are followed during the
development of the device. List the
standard, guideline, security best
practices that are referenced.
Improve executable security:
evidence showing compiler and
build tools configuration, or internal
documents describing the process
to improve the executable security.
Functional testing of security
features: test document such as
functional testing test case
document or test tool report
describing the test cases (purpose
and steps of each test case), or
internal document(s) describing the
process to conduct functional
testing.
Developer and/or peer code
review: Internal document or
evidence of the tracking system
used for tracking the code review
feedback and remediation status of
the findings.
Static application security testing
(SAST): test report describing the
CLS Publication #2 | Page 45 of 49