At the core of CLASP are 24 security-related activities that can be integrated into a software development process. The activities phase translates into executable software the subset of the 24 security-related activities which were assessed and accepted in the implementation phase.

CLASP also has an impact on several key traditional software engineering activities, such as requirements specification. CLASP does not materially change the steps within such activities. Instead, it recommends extensions to common artifacts and provides implementation guidance for security-specific content.