Leaders and managers in enterprises need to understand several key topics if they expect to successfully address software risk for their organizations. This presentation begins by examining some well-publicized breaches and the core failures that allowed these breaches to occur. Then it expands on these issues to enumerate several critical – but common – mistakes that enterprises make when crafting their Software Security Assurance (SSA) programs. Finally, the presentation lays out foundations for a healthy, well-functioning SSA program that are independent of whatever framework – SDL, BSIMM, OpenSAMM – that your team may use.