Project-specific controls
Security requirements should be assessed against the data and risks of each project. Access controls, encryption, validation, dependency review and testing can be included in the agreed scope; this page is not a guarantee that every control applies to every system.