Software manufacturers should implement a secure software development program that supports and enhances the security and quality of both products and development environments, new joint guidance from U.S. and Australian government agencies highlights.
See also: Many businesses believe that employees lack “cybersecurity knowledge”

It aims to help software developers ensure that products are reliable and secure for customersby establishing secure software development processes. The document, written by the US cybersecurity agency CISA, the FBI and the Australian Cybersecurity Security Centre (ACSC), also provides guidance for effective deployments as part of the software development life cycle (SDLC).
Released as part of CISA's Secure by Design push, the new guidance, " Secure Software Development: How Software Builders Can Ensure Trust for Customers, " is appropriate for developers of cloud- based software or services , CISA, FBI, and ACSC.
See also: CISA: New security requirements for the protection of personal and government data
Mechanisms that can help deliver high-quality software through a secure software development process include strong quality assurance processes, early problem detection, a well-defined development strategy that includes phased release, comprehensive testing strategies, feedback loops for continuous improvement, collaboration, short development cycles , and a secure development ecosystem.

Creation companies encourage software developers to define goals, customer needs, potential risks, costs, and success criteria during the design phase and to focus on coding and continuous testing during the development and testing phase.
They also note that developers should use books on secure software development processes, as they provide guidance, best practices , and contingency plans for each phase of development, including detailed steps for dealing with emergencies, both during and after development.
See also: Microsoft: Cyberattacks increase to 600 million
Additionally, software manufacturers should implement a plan for notifying customers and partners when a critical issue arises and should provide clear information about the issue, impact, and resolution time.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
