Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Secure Development

Controls to secure the development pipeline and perform source code quality assurance.

Last updated 24 March 2026

SD-1: Push Protection for Secrets

Control Statement

Control Recommendations

Risk Statement

SD-2: Default Branch Push Permissions

Control Statement

Control Recommendations

Risk Statement

SD-3: Continuous Integration (CI) Tests

Control Statement

Control Recommendations

Risk Statement

SD-4: Static Analysis

Control Statement

Control Recommendations

Risk Statement

Parameters

SD-5: Dependency Scanning

Control Statement

Control Recommendations

Risk Statement

Parameters

SD-6: Secret Detection

Control Statement

Control Recommendations

Risk Statement

Parameters

SD-7: CI Environment Variable Secrets Management

Control Statement

Control Recommendations

Risk Statement

SD-8: Deployment Environment Segregation

Control Statement

Control Recommendations

Risk Statement

SD-9: Dynamic Analysis

Control Statement

Control Recommendations

Risk Statement

Parameters

SD-10: Secure Software Development Lifecycle (SSDLC)

Control Statement

Control Recommendations

Risk Statement