Typical severity: High. Likelihood of attack: Medium. An adversary uses their privileged position within an authorized development organization to inject malicious logic into a codebase or product.
Assess software and hardware during development and prior to deployment to ensure that it functions as intended and without any malicious functionality. This includes both initial development, as well as updates propagated to the product after deployment.