The Insecure Software Development Lifecycle How to find, fix, and manage deficiencies within an existing methodology

No ratings

Presented at HackinParis2018 2018 by

As security practitioners, we know what "secure software" is, but we do not always know how to actually achieve software assurance in the way we want it. Many valid questions arise when trying to fix a development function that does not think it has time or resources to create securely: How should you evaluate an existing software development program? What do you do once you’ve identified deficiencies in a process? How do you inject security into the organization’s framework? When insecure methods for creating and maintaining software have already been established, but the program does not include security or compliance, there are practical techniques you can use to elicit change, such as obtaining buy-in from stakeholders and closing process gaps. Any existing software development methodology can be updated to ensure security becomes a mandatory consideration at every step of the SDLC.