Verificando autenticación…

Skip to main content

Security in Software Development

Software development at Grupo LATAM is governed by mandatory security guidelines that apply from design through to production, under the Security by Design approach and aligned with industry frameworks (OWASP, PCI-DSS, NIST) and applicable regulations (GDPR, LGPD, SOX).

This section summarizes the two corporate documents every development team must know and comply with:

DocumentCodeWhat it defines
Secure Development NormGRT.NOR.0062Mandatory security guidelines (lifecycle)
Secure Coding StandardGRT.EST.010Technical S-SDLC controls by domain
Mandatory compliance

Both documents are mandatory for all internal staff, collaborators, and third parties involved in software development or management at LATAM. Non-compliance is subject to disciplinary measures.

Relationship with this documentation

These guidelines complement the Best practices section (authentication, API security practices, and encryption) and the use of Golden Paths and LATAM-validated templates, which already incorporate many of these controls by default.