G.5 Assess and manage risk

Proactively analyzing, mitigating, and managing software supply chain risk and achieving the objectives of a software security program.

Controls

G.5.1 Criticality analysis

Identify critical system components and functions by performing a criticality analysis.

G.5.2 Track security risks and decisions

Record and track the software’s security risk-based exceptions and mitigation plans.

G.5.3 Security metrics

Provide the basis for the measurement of an effective plan for tracking and realizing software security objectives within an organization.

G.5.4 Data-informed product decisions

Make security decisions on software release based upon criteria for checking the security of the software.