Summary
Helps vendors measure how well they meet the Software Security Code of Practice, and suggests remedial actions should they fall short. This document allows technical staff to self-assess their own software practices against the Software Security Code of Practice, a set of outcomes that – if met – means the vendor can claim that their software has achieved a baseline of software security and resilience. This document considers each principle within the four themes in the Code, and breaks them down into a set of individual claims that describe a way to fully meet the associated principle. If all these claims are well-evidenced, then a vendor can claim in good faith that they are meeting the principle. The type of evidence can vary but examples include document inspection, interviewing individuals, or auditing test plans and results. Vendors requiring independent audit of compliance with the code should contact any NCSC-approved cyber resilience test facility.