NIST SSDF: PO — Roles & Responsibilities
warningssdf_po_roles_defined
Roles and responsibilities for the secure development process are defined (PO.2).
Formula
G(Release → P(security_roles_defined)) Why it matters
SSDF PO.2: implement roles and responsibilities, and provide role-based training, for the SDLC.
Examples
passes the practice's evidence is present
fails the required secure-development step is absent
Use it
ponens policies add ssdf_po_roles_defined --into ./trace.json
ponens trace check ./trace.json