| name | RV.3.4_rv34 |
| description | Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or |
| category | configuration |
| version | 1.1 |
| author | cyberstrike-official |
| tags | ["nist","sp800-218","ssdf","rv-3-4","rv","secure-development","task"] |
| tech_stack | ["any"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | ["Analyze Vulnerabilities to Identify Their Root Causes (RV.3)"] |
| severity_boost | {} |
RV.3.4 RV.3.4
Task of practice: Analyze Vulnerabilities to Identify Their Root Causes (RV.3)
High-Level Description
Practice Group: Respond to Vulnerabilities (RV)
Framework: NIST SP 800-218 SSDF v1.1
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or in new software that is created.
What to Check
How to Test
Step 1: Review SDLC Documentation
Examine development lifecycle documentation for evidence of RV.3.4 practice implementation.
Step 2: Verify Tooling
# Check CI/CD pipeline configuration
# Verify security tools are integrated
# Example: Check for SAST/DAST in pipeline
grep -r "security\|scan\|sast\|dast" .github/workflows/ 2>/dev/null
grep -r "security\|scan" Jenkinsfile 2>/dev/null
Step 3: Assess Developer Awareness
Verify development team understands and follows RV.3.4 RV.3.4 practice.
Tools
| Tool | Purpose | Usage |
|---|
| github-security-mcp | Check repository security settings | github_security_* tools |
| Manual Review | SDLC process review | Documentation and interviews |
Remediation Guide
Implement RV.3.4 RV.3.4 in the software development lifecycle:
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or in new software that is created.
Risk Assessment
| Finding | Severity | Impact |
|---|
| RV.3.4 RV.3.4 not implemented | Medium | Secure Development - Respond to Vulnerabilities |
CWE Categories