Turn your SAP BTP secure-development policy into enforceable, testable requirements developers and reviewers can apply.
Policies say what must be true. Standards say exactly how — the specific, checkable requirements that make secure development real on SAP BTP.
This standard covers the full BTP build surface: CAP and RAP services, AppRouter and XSUAA security descriptors, Kyma container images, dependency and software-composition controls, secret handling, CI/CD quality gates, and governed transport — each expressed as concrete requirements, not aspirations.
It is grounded in the SAP BTP Secure Configuration Baseline and mapped to OWASP, the NIST Secure Software Development Framework, CIS, and SAP secure-development guidance, so every requirement is defensible.
What this replaces
- Ad-hoc, reviewer-by-reviewer interpretations of “secure enough”
- Generic secure-coding checklists that don’t understand BTP (XSUAA, CAP/RAP, Kyma, CTMS)
- Weeks of a specialist writing your development and extension standard from scratch
What you get
- A configurable Microsoft Word standard — fully editable, professionally formatted, and ready to adopt:
- 19 enforceable requirement areas plus framework alignment across the BTP development and extension surface
- A per-object-type control matrix across ten BTP development object types (CAP/RAP, XSUAA, AppRouter, Kyma, Cloud Foundry, and more)
- An XSUAA scope and descriptor specification, a destination and credential-source pattern catalogue, and a required HTTP security-header table
- Object classification, naming conventions, a prohibited-pattern list, and a code validation and release checklist
- Bracketed placeholders ([Severity Threshold], [Control Frequency], [Patch Cadence]) to fit your risk appetite
- Both Organization and Consultancy license editions
