60 likes | 308 Views
Secure Coding: SDLC Integration Sixfold Path. Problem Set. Secure Coding Requirement. Security Organization. Development Organization. The Business. Landscape of Methodologies. Problem: Either too general Or custom tailored – not Business focused!. BSIMM. Microsoft SDL. OWASP CLASP.
E N D
Problem Set Secure Coding Requirement Security Organization Development Organization The Business
Landscape of Methodologies Problem: Either too general Or custom tailored – not Business focused! BSIMM Microsoft SDL OWASP CLASP SAMM AGILE TSP-Secure Software CBK
SixFold Path to Secure Coding in SDLC • Right Leaders • Security • Business • Development • Right Plan • Phased approach • Education • Developers • Business / Management • Right Process • SDLC Integration • Tools
SixFold Path to Secure Coding in SDLC • Right Skill sets • Language SME’s • Vulnerability Assessment / Identification • Understanding of SDLC, Project Mgmt, and Risk Mgmt • Right Policies • Right Traceability • Centralized and standardized code framework • Defect tracking of vulnerabilities • Standard reporting regardless of tool/approach • Metrics • Governance
Planning / Requirements Development QA