Software Vulnerability Testing Using SAST, DAST and SCA
Software is regularly tested for security vulnerabilities using various testing methods before and after release.
Plain language
This control ensures that software is thoroughly checked for security weaknesses before and after it's launched. If missed, these weaknesses could become easy targets for hackers, leading to stolen data or financial losses.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
Software is comprehensively tested for vulnerabilities using SAST, DAST and SCA prior to its initial release, any subsequent release, and periodically to help identify any previously unidentified vulnerabilities.
Why it matters
Unaddressed software vulnerabilities can lead to potential breaches, data loss, and significant financial damages.
Operational notes
Maintain up-to-date knowledge of security tools and regularly update testing protocols to address new vulnerabilities.
Implementation tips
- System owners should schedule regular vulnerability scans: Allocate time before each software release to conduct vulnerability checks. Use tools that automatically scan for known issues.
- IT team should conduct Static Application Security Testing (SAST): This involves reviewing the software's code for vulnerabilities. Train team members to use specific software tools that highlight potential security flaws in the code.
- IT security personnel should employ Dynamic Application Security Testing (DAST): This type involves testing running applications for vulnerabilities. Use tools that simulate attacks to identify and fix security gaps before software is deployed.
- Procurement should source Software Composition Analysis (SCA) tools: These tools scan for vulnerabilities in third-party components. Ensure that the team remains aware of vulnerabilities in open-source libraries by integrating SCA in the development lifecycle.
- Managers must ensure periodic reviews post-release: Schedule ongoing security evaluations at regular intervals after software goes live. Confirm that assessments keep up with new threats by updating tools and techniques as needed.
Audit / evidence tips
- Askthe most recent SAST testing report: Request records showing when and where code was reviewed for vulnerabilitiesLook atindications that all critical code areas were assessedGoodis a detailed report showing the vulnerabilities discovered and fixed
- Aska log of DAST assessments: Request documentation demonstrating that dynamic tests were conducted on running applicationsLook atevidence that testing covered all application functionalitiesGoodshows test results with identified issues and the steps taken to mitigate them
- AskSoftware Composition Analysis records: Request a list showing results from scanning third-party componentsLook atwhether all dependencies have been analysed for weaknessesGoodincludes a clear record of outdated or vulnerable components and actions taken to address them
- Askmeeting notes from post-release security evaluations: Request documentation of any discussions conducted to review security findingsLook atschedules and frequency of these meetingsGoodwould demonstrate regular and consistent review cycles with documented outcomes
- Aska vulnerability management policy: Request any documents detailing how new vulnerabilities are tracked and addressed over timeLook atdetails on responsible personnel and patching timelinesGoodwould display a proactive approach to updating and securing software
Cross-framework mappings
How ISM-0402 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 8.25 | ISM-0402 requires comprehensive vulnerability testing (including SAST, DAST and SCA) prior to release and periodically thereafter | |
| Annex A 8.29 | ISM-0402 requires comprehensive software vulnerability testing using SAST, DAST and SCA before initial release, subsequent releases, and ... | |
handshakeSupports(2)expand_less | ||
| Annex A 8.28 | Annex A 8.28 requires secure coding principles to be applied to prevent vulnerabilities during software development | |
| Annex A 8.30 | ISM-0402 requires comprehensive vulnerability testing (SAST, DAST, SCA) before release and periodically to identify previously unknown vu... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-PA-ML1.2 | E8-PA-ML1.2 requires that organisations use a vulnerability scanner with an up-to-date vulnerability database for vulnerability scanning ... | |
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 6.2.4 | Annex A 6.2.4 requires documented AI system verification and validation measures and criteria for their use | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.