# SP-041 Secure Application Baseline for Developers

Status: deprecated. Release 26.02. Modified 2026-03-14. Licence: CC BY-SA 4.0.
Deprecated. Superseded by SP-028.

Scope: Architecture pattern bridging the gap between security control frameworks and practical software implementation. Provides developer-centric guidance for each control area: how to detect what is already implemented, how to identify gaps against control requirements, and how to implement what is missing in a modern application stack.
Use when: Engineering teams building cloud-native applications who need to satisfy security control requirements. Startups and scale-ups approaching their first security review or compliance certification.
Not when: Organisations with mature security engineering practices and established internal implementation guides.

## Controls (32, NIST SP 800-53 ids)
- Critical (6): CM-02, CM-06, CM-07, SC-12, SI-10, SA-11
- Important (19): AC-03, AC-06, IA-02, IA-05, IA-08, SC-08, SC-28, SC-07, SC-13, SI-07, SI-15, SR-03, SR-04, SA-04, SA-15, CM-03, CM-14, AU-02, AU-03
- Standard (7): AU-06, AU-12, AC-04, CA-07, CA-02, PL-02, PM-14

## What each critical control mitigates (6)
- CM-02 Baseline Configuration: T-41-001, T-41-002, T-41-011
- CM-06 Configuration Settings: T-41-001, T-41-002
- CM-07 Least Functionality: T-41-007
- SC-12 Cryptographic Key Establishment And Management: T-41-003
- SI-10 Information Accuracy, Completeness, Validity, And Authenticity: T-41-005, T-41-010
- SA-11 Developer Security Testing: T-41-004, T-41-008, T-41-011

## Threats and the controls that mitigate them (12)
- T-41-001 Implementation gap — Security controls exist in policy documents but lack corresponding technical implementation, leaving the system unprotected despite paper compliance: CM-02, CM-06, CA-07
- T-41-002 Configuration drift — Infrastructure and application configurations diverge from declared baselines over time through manual changes, hotfixes, and undocumented modifications: CM-02, CM-06, CM-03
- T-41-003 Secrets exposure — Credentials, API keys, and cryptographic material committed to source code, embedded in container images, or stored in plaintext configuration files: SC-12, SC-28, IA-05
- T-41-004 Supply chain compromise — Malicious or vulnerable dependencies introduced through package managers, container base images, or CI/CD tooling without detection: SR-03, SR-04, SA-04, SA-11
- T-41-005 Injection attacks — SQL injection, NoSQL injection, command injection, and cross-site scripting through unvalidated user input reaching backend systems: SI-10, SI-15, SC-08
- T-41-006 Broken authentication — Custom or misconfigured authentication allowing session hijacking, credential stuffing, token theft, or privilege escalation: AC-03, AC-06, IA-02, IA-08
- T-41-007 Container escape and lateral movement — Containers running with excessive privileges enabling breakout to host, access to other workloads, or cluster compromise: CM-07, SC-07, SI-07
- T-41-008 Pipeline compromise — Attacker modifies CI/CD pipeline to inject malicious code, exfiltrate secrets, or deploy backdoored artifacts to production: SA-11, CM-14, SI-07, SA-15
- T-41-009 Insufficient logging — Security-relevant events not captured, logged in unparseable format, or not forwarded to monitoring, preventing detection and forensic investigation: AU-02, AU-03, AU-06, AU-12
- T-41-010 API abuse — Unauthenticated, unrate-limited, or improperly validated API endpoints exploited for data exfiltration, denial of service, or business logic manipulation: SC-08, AC-04, SC-13, SI-10
- T-41-011 Tribal knowledge dependency — Security implementation knowledge concentrated in individuals rather than codified in automation, creating single points of failure and inconsistent application across teams: CM-02, SA-11, PL-02, SA-15
- T-41-012 Compliance theatre — Organisation satisfies audit through manual evidence collection and point-in-time assessments rather than continuous automated verification, leaving security gaps between audit cycles: CA-07, CA-02, AU-06, PM-14

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-041/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-041/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 30 KB: /api/v1/patterns/SP-041
- Page for people: /patterns/sp-041/
- Related: SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline; SP-030 API Security; SP-012 Secure Software Development Lifecycle

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
