-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
As mentioned previously, secure coding can be difficult to achieve as it is not often taught in schools. Many developers, if they have the time, research secure coding practices either at work or while they are at home in their free time. Resources have been created to assist with the methods of secure coding; the problem is just finding the best method for your needs.
Three organizations stand out in providing secure coding practices: NIST, the Software Engineering Institute (SEI) at Carnegie Mellon University, and OWASP. Both organizations provide material and checklists for how to train your employees and what to look for when evaluating code.
With assistance from BSA, OWASP, and SAFECode, NIST has developed the Secure Software Development Framework (SSDF). The framework laid out in SP 800-218 assists organizations in establishing a method for maintaining software throughout the SDLC. The criteria for the SSDF are as follows: