Secure design & implementation
Eliminate, substitute, or reduce unacceptable risks through secure design and controlled implementation.
Gate
G3
Design output baseline approved
Target date
30 Sept 2026
Gate review
Open blockers
2
must close before the gate
Accountable
Engineering Manager
Security Architect advises; Product Owner accepts tradeoffs
Open blockers on G3 (2)
Each must close before the gate can pass.
Unowned HIGH vulnerability: VMR-0142 (third-party BLE stack buffer overflow) has no assigned owner or disposition. Gate rule: no unowned critical/high vulnerability.
Owner Tomas Novak · R&D Manager
Verification-ready configuration baseline not frozen: PSCG-0042 v0.9 still in review and configuration drift detected on two verification test units.
Owner Priya Raman · Security Architect
Implement controls, secure architecture, component governance, configuration, provenance, and vulnerability analysis.
- Prefer design-level prevention over downstream detection.
- Every treatment has an implementer, control objective, and verification method.
- Approved inputs and risk baseline
- Detailed design and implementation plans
- Supplier component information
- 1Implement risk controls and secure-by-default configuration
- 2Apply secure coding, code review, signing, secrets, build provenance, and change control
- 3Create component inventories and vulnerability dispositions
- 4Update architecture, risk, requirements, and traceability as design changes
- Updated PSAD and PSRA
- Cybersecurity Bill of Materials with SBOM/HBOM views
- Vulnerability Management Register
- Product Security Configuration Guide
- Implementation evidence
- Control implementation reviewedOpen
- No unowned critical/high vulnerabilityFailing BLK-0031
- Component provenance and supplier obligations completeOpen
- Verification-ready configuration baselinedFailing BLK-0032
- Accountable
- Engineering Manager accountable
- Supporting
- Security Architect advises; Product Owner accepts tradeoffs
- Risk (pending)
- Option analysis (pending)
- Design decision (pending)
- Requirement (pending)
- Control (pending)
- Implementation (pending)
- Uncontrolled unacceptable risks
- Preventive-control ratio
- Treatment aging