Integrate application security across the SDLC — design reviews, testing, dependency risk, and secure release criteria. Use when hardening products, building AppSec programs, or preparing applications for hostile input environments.