Concept and mechanism
Security engineering should accompany requirements, design, implementation, and operation. Final SSDF 1.1 provides lifecycle practices; consulted revision 1.2 remains draft and should not be presented as a final standard. The pipeline needs to preserve artifact identity: testing one digest and later deploying a mutable tag can deliver different content. Provenance helps relate an artifact to its build process but requires checking authenticity, builder identity, and expected policy. A valid signature from an untrusted identity does not resolve that decision. Record the exact approved content and the conditions under which results apply.
Guided application
In a fictional project, Terraform marks a password sensitive. That can hide display, but state may still store it; protect state, plans, and access, considering ephemeral mechanisms only where version and provider support them. In Ansible, check mode helps anticipate changes, but unsupported modules and conditions based on registered results limit simulation. Diff can reveal secrets and needs targeted handling. For Linux pods, Restricted combines privilege limits, non-root execution, and other restrictions; one field does not establish complete compliance. Before release, rehearse data-aware rollback too: returning to an earlier binary does not automatically undo an incompatible schema. Acceptance should connect execution and final state, leaving gaps explicitly open.
Digest A tested and tag now at B: validate B or deploy A, without transferring approval by name.
Common pitfalls
sensitive as state removal; check as complete rehearsal; signature without trust; rollback without data.
Related topics: Governance, risk, and exceptions · Suppliers, data, and threats · Resilience and recovery dependencies
Maintain a verifiable chain from requirements through build, configuration, and execution.
Reference: Secure Software Development Framework 1.1 · CAS-005 / SecurityX V5; objectives 3.0; launched 2024-12-17