2020
DOI: 10.6028/nist.cswp.04232020
|View full text |Cite
|
Sign up to set email alerts
|

Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)

Abstract: Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure the software being developed is well secured. This white paper recommends a core set of highlevel secure software development practices called a secure software development framework (SSDF) to be integrated within each SDLC implementation. The paper facilitates communications about secure software development practices a… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
18
0
2

Year Published

2020
2020
2022
2022

Publication Types

Select...
3
3
2
1

Relationship

2
7

Authors

Journals

citations
Cited by 21 publications
(20 citation statements)
references
References 2 publications
0
18
0
2
Order By: Relevance
“…Manufacturers should consider which, if any, secure development practices are most appropriate 759 for them and their customers as they further plan how to adequately support customer goals. Manufacturers can answer questions like the following based on expected customers and uses cases to help identify additional action to take towards cybersecurity: [28], which highlights selected practices for secure software development. Each of these practices is widely recommended by existing secure software development publications, and the white paper provides references from nearly 20 of these publications.…”
Section: Activity 4: Plan For Adequate Support Of Customer Goalsmentioning
confidence: 99%
“…Manufacturers should consider which, if any, secure development practices are most appropriate 759 for them and their customers as they further plan how to adequately support customer goals. Manufacturers can answer questions like the following based on expected customers and uses cases to help identify additional action to take towards cybersecurity: [28], which highlights selected practices for secure software development. Each of these practices is widely recommended by existing secure software development publications, and the white paper provides references from nearly 20 of these publications.…”
Section: Activity 4: Plan For Adequate Support Of Customer Goalsmentioning
confidence: 99%
“…The same recommendations for messaging discussed above apply 725 for follow-up communications, but extra care should be taken to avoid too many or contradictory follow-up messages, which could lead some customers, particularly home customers, to ignore important messages. [22] states, following secure software development practices should help manufacturers "reduce the number of vulnerabilities in released software, mitigate the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. "…”
Section: Support and Lifespan Expectationsmentioning
confidence: 99%
“…There are many existing standards, guidelines, and other publications on secure software development. IoT device manufacturers interested in more information can consult the NIST white paper on secure software development [22] which highlights selected practices for secure software development. Each of these practices is widely recommended by existing secure software development publications, and the white paper provides references from nearly 20 of these publications.…”
Section: Support and Lifespan Expectationsmentioning
confidence: 99%
“…The first row illustrates that the team would consider objectives of the Design phase including planning, and thus would need a Security Architect.Table 3is an informative example and does not cover all the Work Roles that may be present or needed for a given Team. For more information, see NIST's Secure Software Development Framework [6].…”
mentioning
confidence: 99%