top of page
D10S_hero_bkgd_v1_2026.png

D10

DevSecOps & Secure SDLC Engineering

D10-cover-image2.png
About The Standard Domain 

The DevSecOps & Secure SDLC Engineering domain defines how organizations embed security into software delivery and engineering workflows across the entire software development lifecycle.

It establishes expectations for secure development, pipeline enforcement, testing, integrity checks, controlled promotion, and evidence-backed release discipline to reduce risk and deliver trusted software at scale.

Secure Development

Pipeline Security

Verification Gates

Release Integrity

Evidence & Traceability

Why Adoption is Necessary

Architectural Clarity

 

Provides a shared blueprint for integrating security into SDLC processes, roles, tools, pipelines, and engineering workflows.

Consistent Engineering Expectations

Aligns teams on DevSecOps controls, pipeline practices, quality gates, release discipline, and security requirements.

Measurable Verification

Defines verifiable security gates and quality checks across the pipeline for continuous validation.

Stronger Evidence 

Supports traceable build, test, release, and deployment evidence for assurance, accountability, and compliance.

How The Standard Works

Requirements

Define the security and quality requirements for code, pipelines, artifacts, and releases to ensure trusted software delivery.

Technical Specifications

Provide the methods, controls, and tooling specifications needed to implement secure SDLC and DevSecOps practices.

Verification and Validation

Define how to test, scan, verify, and validate pipeline gates, releases, and artifacts for trust and integrity.

Implementation Guidance

Offer practical guidance, patterns, and best practices to implement DevSecOps and secure SDLC engineering effectively.

Associate Standards Preview

Associate Standards Coming in Q3 2026 

Detailed, implementation-level standards that support D01 will be published in Q3 2026 to help teams operationalize secure network architectures.

D10S_ISAU_shield_logo_v2_2026_transp.png
Built for Builders. Backed by Evidence.

D10 provides the architectural foundation for DevSecOps and secure SDLC engineering, designed, engineered, and proven to secure code, pipelines, builds, releases, deployments, and software delivery evidence.

Governance by:

ISAUnited-red_trimmed.png

Training by:

Practitioner and Organizational Use

The Defensible 10 Standards (D10S) are published under a Creative Commons Attribution–NonCommercial 4.0 International License (CC BY-NC 4.0).


This license permits free use, adaptation, and internal implementation of the D10S by individual practitioners, educational institutions, and organizations for the purpose of research, training, architecture design, or internal security engineering.


Attribution to ISAUnited.org must be maintained in all uses, reproductions, or derivative works.

Commercial, Vendor, and Integration Use

The use, reproduction, or incorporation of the Defensible 10 Standards (D10S) or their content within commercial products, software, tooling, managed services, or for-profit offerings requires a separate commercial integration or redistribution license issued by the Institute of Security Architecture United (ISAUnited.org).


This includes but is not limited to:

  • Integration into commercial or subscription-based platforms or software tools

  • Use in vendor-branded frameworks or automated compliance products

  • Redistribution of modified or adapted versions for resale or commercial benefit

 

Requests for commercial licensing or integration agreements should be directed to:  info@isaunited.org

© 2026 The Defensible 10 Standards (D10S). Owned, operated, and maintained by the Institute of Security Architecture United (ISAUnited.org).

bottom of page