Secure software development according to the “security by design” principle
Summary
In 2009 heise Developer presented the “security by design” principle practised by companies such as Adobe, Google, Microsoft, Oracle/Sun and Symantec. Security is planned, implemented and tested as an explicit requirement from the start. Applied consistently, it even postpones delivery until security bugs above a defined threshold have been fixed.
Ideas
- Security is formulated as a requirement, not added afterwards.
- Measures range from planning through implementation to testing.
- A threshold for security bugs can stop delivery.
Insights
- Late security fixes are more expensive than measures planned in early.
- A binding release criterion gives security the same weight as functionality.
Facts
- The article named Adobe, EMC, Google, Microsoft, Oracle/Sun and Symantec as users.
- Microsoft’s Security Development Lifecycle is regarded as the model for the approach.
References
Critique
- The report is a pointer to an article and names no methods, costs or metrics.
Recommendations
- For your own projects, define which severity of security bug prevents a release.
- Plan threat modelling and security testing as fixed steps in the development process.
Links to the original source and the Web Archive open in a new tab.