Defining a Secure Software Process
摘要
Many organizations take the view that features are the most important delivery and with limited time and resources, this becomes the focus. At the end, security is added in. The problem with this approach is that deployment may occur with little to no security features. This ensures that the software is defenseless or near defenseless against attackers and data breaches are the inevitable result. This chapter considers the secure software lifecycle, with examples from two commercial standards: Building Security In Maturity Model and PCI's Software Security Lifecycle Requirements, as well as methods to ensure a secure agile development process.