Skip to main content
Guidance

Secure development and deployment guidance

8 Principles to help you improve and evaluate your development practices, and those of your suppliers

Page 2 of 10

Secure development principles

As the way we build software and systems is rapidly evolving, use this list of 8 principles to help you evaluate and improve your development practices.
  • Secure development is everyone's concern Genuine security benefits can only be realised when delivery teams weave security into their everyday working practices.
  • Keep your security knowledge sharp Creating code that is capable of withstanding attack requires an understanding of attack types and of defensive security practices. Your level of understanding in these areas must be regularly updated if it's to remain useful.
  • Produce clean & maintainable code

    If your code lacks consistency, is poorly laid out and undocumented, you're adding to the overall complexity of your system.

  • Secure your development environment

    There is sometimes a perceived conflict between security and usability. This situation is highlighted in the case of end user devices and the environments used to support software development.

  • Protect your code repository Your code is only as secure as the systems used to create it. As the central point at which your code is stored and managed, it's crucial that the repository is sufficiently secure.
  • Secure the build and deployment pipeline

    Continuous integration, delivery and deployment are modern approaches to the building, testing and deployment of IT systems.

  • Continually test your security

    Security testing can be manual, but it can also be automated.

  • Plan for security flaws All but the very simplest software is likely to contain bugs, some of which may have a security impact.

Reviewed

Version

1.0