| # |
Control Group/ Policy |
TSC |
Risk Domain |
FM Policy/ Standard # |
FM Control |
Control Requirement |
Policy/ Directive Verbiage |
Status |
Vendor Policy Name in Folder |
Verbiage or TSC Covering Control (If applicable) |
Remarks |
| 1 |
SOC 2 Type II |
| Information Risk |
IT Third Party SOP |
| SOC 2 Type 2 report provided from within the past 12 months with a period of performance of 12 months (or sufficient bridge letter) OR valid ISO 27001 with a Statement of Applicability and Area of Nonconformities included. |
Policy has not been reviewed since May 2022* In addition to the required assessments through the SRM Procedures, ITRM-TP will
perform additional assessments as deemed necessary. Any documentation provided
outside of periodic vendor risk assessments to Contract Owners to evidence the
confidentiality, availability, and integrity of a supplier’s controls (SOC 2 Type II reports,
etc.) should be sent to ITRM-TP for review. Additionally, ITRM-TP will assess EO+T suppliers which may not have triggered an
assessment based on the completion of the IRA or which may not have an ongoing
assessment done on annual basis. The ITRM-TP assessment will include (at the least)
a review of the supplier’s SOC 2 Type II reports. |
| 2 |
SOC 2 Type II |
| Information Risk |
IT Third Party SOP |
| SOC 2 Type 2 report includes Confidentiality if data classification is above confidential and availability if OR Risk is in scope |
No requirement for SOC 2 to cover any specific trust prinicples based on data access level |
| 3 |
SOC 2 Type II |
| Information Risk |
IT Third Party SOP |
| All deviations contain valid management responses |
| 4 |
Internal Vulnerability Scan |
| Information Risk |
D.SEC.GRC.5.1
Information Security Directives |
| Internal vulnerability Scan provided or SOC 2 Type II control verifying that internal vulnerability scans occur on a minimum of a quarterly frequency with all vulnerabilities tracked to closure. |
On a monthly frequency at minimum, Technology Assets must be scanned for known
vulnerabilities and system security misconfigurations. Scans must be authenticated where
technically feasible. |
| 5 |
Internal Vulnerability Scan |
| Information Risk |
D.SEC.GRC.5.1
Information Security Directives |
| Internal Vulnerability Scan is dated within past three months |
On a monthly frequency at minimum, Technology Assets must be scanned for known
vulnerabilities and system security misconfigurations. Scans must be authenticated where
technically feasible. |
| 6 |
Internal Vulnerability Scan |
| Information Risk |
D.SEC.GRC.5.3
D.SEC.GRC.5.7
Information Security Directives |
| Vulnerability Scan contains a remediation plan or status of any medium or higher risk vulnerabilities identified |
D.SEC.GRC.5.3: Severity of vulnerabilities detected during application security testing, infrastructure
vulnerability scans and penetration testing must include a rating system, based on industry
standard methodologies such as the Common Vulnerability Scoring System (CVSS), and/or
Open Web Application Security Project (OWASP), as applied to Freddie Mac’s
environment.
D.SEC.GRC.5.7: Vulnerabilities identified during Infrastructure scans, penetration testing, and application
security testing are required to be remediated based on severity and the following application
classification within enterprise application repository ( for e.g., Technology Portfolio
Insights): Emergency - 14, Critical, 30, High - 90, Medium - 180, Low - 365 |
| 7 |
External Penetration Test |
| Information Risk |
D.SEC.SE.4.2
Information Security Directives |
| External penetration test provided or SOC 2 Type II control present verifying that external penetration tests occur at a minimum of an annual frequency with all findings tracked to closure. |
Information Security must report results from third-party external penetration testing
exercises, along with status of the remediating actions to address any deficiency, to Freddie
Mac's Internal Regulatory Affairs and applicable stakeholder on a quarterly basis. |
| 8 |
External Penetration Test |
| Information Risk |
D.SEC.SE.4.2
Information Security Directives |
| External penetration test is dated within the past 12 months |
Information Security must report results from third-party external penetration testing
exercises, along with status of the remediating actions to address any deficiency, to Freddie
Mac's Internal Regulatory Affairs and applicable stakeholder on a quarterly basis. |
| 9 |
External Penetration Test |
| Information Risk |
D.SEC.GRC.5.3
D.SEC.GRC.5.7
Information Security Directives |
| External penetration test contains a remediation plan or status of any medium or higher risk vulnerabilities identified |
D.SEC.GRC.5.3: Severity of vulnerabilities detected during application security testing, infrastructure
vulnerability scans and penetration testing must include a rating system, based on industry
standard methodologies such as the Common Vulnerability Scoring System (CVSS), and/or
Open Web Application Security Project (OWASP), as applied to Freddie Mac’s
environment.
D.SEC.GRC.5.7: Vulnerabilities identified during Infrastructure scans, penetration testing, and application
security testing are required to be remediated based on severity and the following application
classification within enterprise application repository ( for e.g., Technology Portfolio
Insights): Emergency - 14, Critical, 30, High - 90, Medium - 180, Low - 365 |
| 10 |
Background check policy |
| Information Risk |
Policy 3-227
Background Checks Policy |
| Criminal Background checks are performed for all new employees prior to gaining access to systems |
All external applicants offered employment with Freddie Mac for non-officer positions must undergo an initial
comprehensive background check which includes, but is not limited to, a criminal records check; social security
number, education, employment, social media screen and professional references verifications; and a drugtest. All external applicants offered employment in officer positions must undergo an initial comprehensive background check
Nothing about system access |
| 11 |
Code of Conduct/Ethics |
| Information Risk |
Freddie Mac Code of Conduct |
| A Code of Conduct is in place and available to all employees |
Code of conduct available on Homefront and renewed every 12 months |
| 12 |
Security Awareness Training |
| Information Risk |
D.SEC.GRC.6.1
D.SEC.GRC.6.2
Information Security Directives |
| Security awareness training is required at hire and annually thereafter |
D.SEC.GRC.6.1: Corporate Policy 6-300 Acceptable Use and Management of End User Technology must be
acknowledged by personnel prior to accessing Freddie Mac Technology Assets. (I reviewed policy and it only states that personnell must comply with various information security policies, nothing about training before access)
D.SEC.GRC.6.2: Information Security must provide role-based security training to personnel with assigned
security roles and responsibilities. Users who are in a role that is required to receive training
must complete the applicable role-based training prior to or within 30 days of transfer and
annually thereafter. (I believe the word "transfer" can also be interpreted as "hire) |
| 13 |
Access Management policies |
| Information Risk |
D.SEC.AC.3.1
Information Security Directive |
| Access is approved prior to being granted |
The creation, disablement, update, or deletion of Entitlements that provide access to Freddie Mac technology assets must be executed using an Information Security approved identity and account management process and system. |
| 14 |
Access Management policies |
CC.62 |
Information Risk |
D.SEC.AC.1.2
Information Security Directives |
| System access is removed in a timely manner following termination (under 24 hours) |
Requests for termination of an employee or contingent worker’s (CW) access (i.e., Network,
Active Directory, VPN and wireless) must be initiated by the employee or CW’s manager
within timelines defined by Human Resources or Contingent Worker Operations. For
automated deprovisioning platforms, revocation must be completed within one business day
of termination day. For manual deprovisioning platforms, revocation must be completed
within two business days of termination day. |
| 15 |
Access Management policies |
| Information Risk |
D.SEC.AC.3.3
Information Security Directives |
| General user access is reviewed semi-annually |
Entitlement owners or Identity sponsors22 must certify identity’s access to Entitlement for
application as per the frequency below:
Access Criticality Application Types23 Frequency/ Access Limit
Privileged -- Certified quarterly
Elevated -- Timebound to 6 months or certified semi-annually |
| 16 |
Access Management policies |
| Information Risk |
D.SEC.AC.3.3
Information Security Directives |
| Privileged user access is reviewed quarterly |
Entitlement owners or Identity sponsors22 must certify identity’s access to Entitlement for
application as per the frequency below:
Access Criticality Application Types23 Frequency/ Access Limit
Privileged -- Certified quarterly
Elevated -- Timebound to 6 months or certified semi-annually
|
| 17 |
Access Management policies |
| Information Risk |
D.SEC.AC.1.4
Information Security Directives |
| Use of shared accounts is tracked, secured, or vaulted |
Identity Sponsor must maintain metadata associated with non-human and shared accounts
including description, asset affiliation, lifecycle status within enterprise identity management
system (“IDMS”).
Note: Account profiles managed by Freddie Mac personnel or reside on Freddie Mac hosted
assets are considered in scope to be managed within enterprise IDMS |
| 18 |
Password Management |
| Information Risk |
D.SEC.AC.4.3
Information Security Directives |
| Minimum of 8 characters password length |
Passwords for other internal accounts and external accounts must be at least 8 characters
long and meet at least three (3) of the five (5) complexity requirements:
• One uppercase alphabetic character
• One lowercase alphabetic character
• Minimum of one number and one symbol
• Must not contain three or more consecutive characters from the corresponding account name
• Must not contain three (3) repeated characters |
| 19 |
Password Management |
| Information Risk |
D.SEC.AC.4.6
Information Security Directives
IT Third Party SOP |
| Passwords must be changed every 90 days if the password length is 8 characters
Passwords must be changed annually if password length is 12 characters or longer
Passwords must be changed annually if MFA is used |
Passwords for accounts must be changed as follows:
• 90 days for production accounts
• 180 days for non-production accounts
• 365 days for accounts assigned to external system accounts
• 90 days for external human accounts
If a password is believed to be compromised; it must be changed immediately. |
| 20 |
Password Management |
| Information Risk |
D.SEC.AC.4.4
Information Security Directives |
| Updated passwords must not be the same as any of the previous 6 (six) passwords used. |
Updated passwords must not be the same as any of the previous ten (10) passwords used. |
| 21 |
Password Management |
| Information Risk |
D.SEC.AC.2.5
Information Security Directives |
| Requirements are in place for lockout after five (5) invalid login attempts and log for invalid logins |
Human accounts (for Internal, External and Consumer identities) must be locked out after a
maximum of five (5) consecutive failed login attempts within a 30-minute period. The
account must be locked out for a duration of 30 minutes from the last failed login or until it
is reset by an authorized administrator or through an approved self-service capability. |
| 22 |
Password Management |
CC7.1, CC8.1 |
Information Risk |
D.SEC.AC.2.3
Information Security Directives |
| Requirements are in place for lockout after inactivity. (60 minutes) |
Human account interactive (for internal, external and consumer identities) sessions must be
terminated after a maximum of 60 minutes of inactivity, and immediately after the user logs
off the system/application. Notifications (or clear indication) of session termination must be
displayed upon terminating the interactive session. |
| 23 |
Data Encryption policy |
| Information Risk |
D.SEC.SE.1.1
Information Security Directives
S11-113.D
Cybersecurity Standard |
| Data at rest is encrypted with a minimum of AES-256 encryption |
7.6.3: Encrypt data at-rest to prevent data from being misused or read by unauthorized
users.
Applied Cryptography Encryption Standards contain FRE requirements |
| 24 |
Data Encryption policy |
| Information Risk |
D.SEC.SE.3.12
Information Security Directives
S11-113.D
Cybersecurity Standard |
| Data in transit if encrypted with tls v1.2 or higher encryption |
7.6.2: Encrypt data in-transit to achieve the following objectives:
• Prevent the data from being read by unauthorized users;
• Enable the data’s recipient to authenticate the sender’s identity; and
• Detect whether the data was altered in transit.
Applied Cryptography Encryption Standards contain FRE requirements |
| 25 |
System Hardening guidelines |
| Information Risk |
D.SEC.AC.4.2
Information Security Directives |
| Default passwords must be changed upon initial login |
Password reset for newly provisioned and temporary password(s) must be unique for each
user and meet complexity requirements. Temporary passwords must be set to change upon
initial login |
| 26 |
System Hardening guidelines |
| Information Risk |
D.SEC.SE.2.7
Information Security Directives |
| Hardening standards include disabling, closing, or removing unnecessary network ports |
Information security must protect End User Technology from possible exploitation or data
exfiltration by managing/blocking USB ports and local network access. |
| 27 |
Patch Management |
| Information Risk |
D.SEC.GRC.5.7
Information Security Directives |
| Patch management timelines are in place (includes servers, databases, end points, and software): Critical patches applied within 30 days, high within 90 days, medium within 180 days. |
Vulnerabilities identified during Infrastructure scans, penetration testing, and application
security testing are required to be remediated based on severity and the following application
classification within enterprise application repository ( for e.g., Technology Portfolio
Insights):
Vulnerability Type Severity Remediation Timeline (days)
All Vulnerability Scans Incl:
Infrastructure
Application Security Testing
(SAST, DAST, FOSS)
Penetration Testing
Emergency 14
Critical 30
High 90
Medium 180
For Penetration Testing only Low 365
For vulnerabilities other than from Penetration Testing identified as a Low severity rating remediation timeline is based on business discretion.
|
| 28 |
Electronic/Physical Data Destruction Policy/Procedure |
| Information Risk |
7-710
Policy on Document Lifecycle and Legal Holds |
| Requirements for adhering to a data retention schedule |
Section III: Managing Records and the Document Lifecylce |
| 29 |
Data Loss Prevention policy (If Restricted-PPI) |
| Information Risk |
D.SEC.GRC.7.2
Information Security Directives |
| Mechanisms must be in place to detect and/or prevent the exfiltration of Corporate
Information as per the Enterprise DLP program scope. |
D.SEC.GRC.7.2
Mechanisms must be in place to detect and/or prevent the exfiltration of Corporate
Information as per the Enterprise DLP program scope. |
| 30 |
Physical & Environmental Security |
| Information Risk |
5-300
Corporate Security Policy |
| Badge access is in place to all corporate facilities |
All individuals entering a Freddie Mac facility must comply with security and identification protocols, including the use of biometric devices", security identification (badges), and a unique personal identification number (PIN) selected by the individual. |
| 31 |
Physical & Environmental Security |
| Information Risk |
5-300
Corporate Security Policy
IT Third Party SOP |
| CCTV cameras are required in entry and exit points of corporate facilities and footage is required to be retained for a minimum of 30 days |
| 32 |
Physical & Environmental Security |
| Information Risk |
HomeFront/ Host & Visitors |
| Visitors to corporate facilities are required to sign in, provide ID, and be escorted |
All visitors must:
Be preregistered by a Freddie Mac host.
Check in at the main reception desk and with building security, if applicable.
Provide a valid, government-issued photo ID. |
| 33 |
Incident Management |
| Information Risk |
S11-101.B
Issue Management Standard |
| Process in place from event detection through reporting/remediation |
The issue management standard lays out the scope which includes:
- Issue Identification and Recording
- Issue Severity Determination
- Issue Remediation
- Issue Monitoring and Reporting
- Issue Downgrade and Closure |
| 34 |
Incident Management |
| Information Risk |
D.SEC.CS.1
Information Security Directives |
| Method in place for monitoring threats or incidents |
D.SEC.CS.1: Security Event Monitoring lays out how Security Events shall be monitored via audit logs. Section D.SEC.CS.1.1 requires that Infrastructure/System Security audit logging records shall be sent to a centralized log
repository for review and analysis. |
| 35 |
Incident Management |
| Information Risk |
S11-202.D
Incident Response Standard |
| Response protocols or individuals in charge for responding are in place and documented |
Section 3: Roles and Responsibilities:
• The Executive Vice President – Enterprise Operations and Technology (“EVP-EOT”) in the Enterprise Operations and Technology (“EOT”) Division, or his or her delegate, is responsible for developing and maintaining an IR plan to prepare for and manage technology and information security related incidents and notifying/escalating to the Crisis Management Team – Executive (“CMT-E”) for IT incidents that meet the escalation criteria defined in the Crisis Management Plan.
• The Chief Data Officer (“CDO”) in the EOT Division is responsible for developing and maintaining an IR plan to prepare to guide participation in the response to data privacy breaches and notifying/escalating to the CMT-E for privacy incidents that meet escalation criteria defined in the Crisis Management Plan.
• The VP-Enterprise Services in the Chief Administrative Officer Division is responsible for developing and maintaining an IR plan to prepare for and manage incidents related to physical facilities and the life and safety of personnel, and notifying/escalating to the CMT-E for facility, security, life, and safety incidents that meet escalation criteria defined in the Crisis Management Plan. |
| 36 |
Incident Management |
| Information Risk |
D.SEC.CS.2.10
Information Security Directives |
| Individual or team responsible for performing forensic analysis is documented |
D.SEC.CS.2.7: Information Security must document information pertaining to all incidents for future reviews. This may include maintenance records, status, analysis reports of evidence gathered during forensics, in accordance with Record and Information Management schedule.
D.SEC.CS.2.10: Analysis of forensic evidence and final reports from a cybersecurity incident are reported to
all authorized parties and dispositioned per the documented incident response process. |
| 37 |
Incident Management |
| Information Risk |
S11-202.A
Crisis Management Standard |
| Process in place to notify customers of an incident in timely manner |
The CM plan must: Contain the list and contact information of key internal and external stakeholders who may have a role in
responding to, or must be notified of, a crisis |
| 38 |
Incident Management |
| Information Risk |
S11-202.A
Crisis Management Standard |
| Communication plans are in place for incidents |
The CM plan must: Establish criteria and protocols for communications and escalations to relevant internal stakeholders, Establish criteria and protocols for communication to external parties, such as the Federal Housing Finance
Agency, law enforcement agencies, other governmental organizations, vendors, customers, investors and
the media7 |
| 39 |
Incident Management |
| Information Risk |
D.SEC.CS.2.7 & D.SEC.CS.2.8
Information Security Directives |
| Process for reporting and logging incidents |
D.SEC.CS.2.7
Information Security must document information pertaining to all incidents for future
reviews. This may include maintenance records, status, analysis reports of evidence gathered
during forensics, in accordance with Record and Information Management schedule.
D.SEC.CS.2.8
Information Security must have a capability to allow Freddie Mac Personnel to report
suspected events and triage them for further analysis or escalation. |
| 40 |
Incident Management |
| Information Risk |
S11-109.D
Root Cause Analysis Standard |
| Process for performing a root cause analysis |
Section: III. Root Cause Analysis |
| 41 |
Business Continuity Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Requirement for performing a business impact analysis annually |
BIAs and BCPs must be reviewed, updated, and approved by their respective DROs on a rolling 12-month
cycle, or more frequently if significant changes occur that could impact the plan’s effectiveness. |
| 42 |
Business Continuity Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Roles and responsibilities are defined in the BCP |
Include the roles, responsibilities, and contact information of key internal and third party stakeholders who
may be involved in recovery efforts. |
| 43 |
Business Continuity Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Process for addressing loss of people, loss of technology, loss of location, etc |
Disaster Recovery Plans are required to:
• Identify technology and information assets (both internal and third party) and their dependencies that
support relevant business functions
• Identify applicable recovery criteria for assets and services contained in the plan |
| 44 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Roles and responsibilities are defined in the Disaster Recovery Plan |
V. Disaster Recovery:
DRPs, testing, and plan maintenance are required for all IT assets and services. DRPs define the procedures and
resources required to restore services following a disruption.
Disaster Recovery Plans are required to:
• Include the roles, responsibilities, and contact information of key internal and third party stakeholders who
may be involved in recovery efforts |
| 45 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| A process to be followed in the event of a disaster is defined |
Disaster Recovery Plans are required to:
• Include the sequence in which technology and information assets should be recovered
• Identify applicable recovery criteria for assets and services contained in the plan |
| 46 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Communication plans are in place in the disaster recovery plan |
Disaster Recovery Plans are required to:
Define communication needs and pathways not covered by communication protocols in the BCPs and the
Crisis Management Plan5 |
| 47 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.C
Disaster Recovery Testing Standard |
| Requirement for testing the disaster recovery plan annually |
DRPs must be tested annually |
| 48 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.C
Disaster Recovery Testing Standard |
| Requirement to perform lessons learned and update plan when necessary |
Testing Requirement:
Analyze lessons learned to identify opportunities to enhance technology availability, recovery
capabilities, and testing |
| 49 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| RTOs/RPO for systems and infrastructure supporting FRE services are in place |
Business-expressed process recovery time objectives and recovery point objectives |
| 50 |
Disaster Recovery Plan |
| Operational Resiliency |
S11-202.B
Business Continuity Management Standard |
| Identification of third party dependencies (utilities, service providers, etc) |
Disaster Recovery Plans are required to:
Identify technology and information assets (both internal and third party) and their dependencies that
support relevant business functions |
| 51 |
Disaster Recovery Test |
| Operational Resiliency |
S11-202.C
Disaster Recovery Testing Standard |
| Disaster Recovery Test dated within the past 12 months with test scope and results defined |
IV. Testing Requirements
• DRPs must be tested annually; each test plan must include:
- Test scope, objectives, and schedule
- A test scenario used to identify the scope, severity, and duration of the simulated disruption
- Testing roles and responsibilities of plan stakeholders
- Test procedures designed to evaluate the preparedness of the organization to respond to technology
disruptions and achieve recovery objectives
- Requirements for documenting test results |
| 52 |
Information Security Policy/ Backup Policy |
| Operational Resiliency |
D.SEC.SE.1.2
Information Security Directives |
| Backups are encrypted |
Freddie Mac’s Corporate Information and data when at-rest must be encrypted as per Cybersecurity Standard’s (S11–113.D) Applicable Standard of Care. |
| 53 |
Third Party Risk Management Policy |
| Third Party Risk |
11-225
Third Party Risk Policy |
| Process in place to evaluate third parties based on risk prior to signing a contract |
This Policy establishes the Life Cycle, Third Party types, scope, roles and responsibilities and governance requirements.
The Related Standards further define responsibilities and minimum mitigating controls and requirements for managing the
risks of each Third Party type across the Life Cycle, which consists of the following five stages:
- Risk Assessment
- Due Dilligence in Third Party Provider Selection
- Contract Negotiation
- Ongoing Monitoring
- Termination |
| 54 |
Third Party Risk Management Policy |
| Third Party Risk |
11-225
Third Party Risk Policy |
| Process in place to evaluate third parties' information security practices on an ongoing basis |
This Policy establishes the Life Cycle, Third Party types, scope, roles and responsibilities and governance requirements.
The Related Standards further define responsibilities and minimum mitigating controls and requirements for managing the
risks of each Third Party type across the Life Cycle, which consists of the following five stages:
- Risk Assessment
- Due Dilligence in Third Party Provider Selection
- Contract Negotiation
- Ongoing Monitoring
- Termination |
| 55 |
Change Management/ SDLC |
| Technology Risk |
S11-132.E
Software Development Standard |
| Requirement for approval prior to implementing changes into production |
All activities of the requirements process must be organized in an enterprise-approved system that provides detailed requirement traceability and control capabilities and is compliant with the Identity and Access Management Standard. |
| 56 |
SDLC |
| Technology Risk |
S11-132.E
Software Development Standard |
| SDLC includes the end-to-end SDLC process from requesting change to implementing and validating in production |
S11-132.E: Section: Requirements (Foundational Requirements, Implementation, Develop, Test, Release, and Deploy) |
| 57 |
SDLC |
| Technology Risk |
D.SEC.SA.1.6
Information Security Directives |
| Requirement in place for performing a risk assessment on software and applications |
Non-production services that may traverse into production (or are accessible from production) must be subjected to risk assessment prior to approval by Architecture Review Board4 to confirm the risk to confidentiality, integrity and availability of Corporate Information is considered and understood prior to approval. |
| 58 |
|
| Technology Risk |
D.SEC.SA.1.7
Information Security Directives |
| Requirement for restriction of developers accesing the production environment |
Traffic from designated developer’s endpoint devices (e.g., laptops/desktops) must be
physically or logically separated from the production network. If the production network is
utilized as transport, access to a non-production environment must only be permitted via the
following methods: 1) a point-to-point virtual private network (VPN), 2) virtual desktop
(VDI), 3) designated jump-hosts, or another Corporate Information Security approved
solution. No direct access from development environments to production environments is
authorized unless the non-production environment has equivalent assurances for
Confidentiality, Integrity, Availability, and for Change Management, as does production. |
| 59 |
SDLC |
| Technology Risk |
D.SEC.SA.2.2
Information Security Directives
S11-132.E
Software Development Standard |
| Requirement in place for testing code before going into production |
Freddie Mac Technology Assets (including new applications) that are developed in-house or have in-house developed custom code components must go through Static Application Security Testing (SAST) to identify security vulnerabilities prior to production release. Remediation of findings must be as per the Vulnerability Remediation Timeline requirements stated in these directives.,
S11-132.E Section: Test |
| 60 |
SDLC |
| Technology Risk |
S11-132.E
Software Development Standard |
| Requirement to perform peer review over code before going into production |
Define a peer review process for code and other implementation artifacts. |
| 61 |
SDLC |
| Technology Risk |
D.SEC.SA.2.2
Information Security Directives |
| Requirement for static code scanning before going into production |
Freddie Mac Technology Assets (including new applications) that are developed in-house or have in-house developed custom code components must go through Static Application Security Testing (SAST) to identify security vulnerabilities prior to production release. |
| 62 |
Cloud Security/ Cyptology Policy |
| Technology Risk |
D.SEC.SE.1.1
Inormation Security Directives |
| Sufficient cloud security controls are in place including key management practices |
D.SEC.SE.1.1
Information Security must identify applicable cryptographic protocols, algorithms, key sizes,
key storage, data at rest usage patterns. A schedule for deprecated cryptographic components
must be published, to help ensure Freddie Mac Technology Assets remain in compliance.
All internal, external services and technology associated with the management of keys used
to protect Corporate Information must be developed and maintained in alignment with
relevant Cryptographic directives. |