"Secure Software Lifecycle for Open Source Software" according to the German Federal Office for Information Security (BSI)

https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03185/BSI-TR-03185-2.pdf

They're perfectly reasonable and even half-decent projects should have no problems complying.