Skip to main content
Guidance

Secure development and deployment guidance

8 Principles to help you improve and evaluate your development practices, and those of your suppliers

Page 4 of 10

Keep your security knowledge sharp

Creating code that is capable of withstanding attack requires an understanding of attack types and of defensive security practices. Your level of understanding in these areas must be regularly updated if it's to remain useful.

Fortunately, languages, frameworks and technology stacks often provide functionality to help us write 'good' code. These tools and features are regularly updated and improved, solving common issues while introducing new concepts. And that's the problem in a nutshell. Taking advantage of these new features (whether or not they are security related) requires an investment of time.

You can often avoid compromise by taking advantage of readily-available security features or techniques, but to do so you must know of their existence. You also need to understand how attackers work, and have the ability to discern the relevant feature or technique which will prevent a successful attack.

Teams armed with up to date information are much more likely to implement appropriate defensive controls in their code. At the very least they will know to seek specialist security input for unusual or particularly complex problems, and for code that simply requires a higher level of confidence.

Actions

  • 1

    Developers should be aware of common security threats to their code

    If they do not already have this knowledge, resources should be provided so that it can be gained. Examples may include standard injection techniques and handling untrusted input.

  • 2

    Use your developer recruitment process to screen for basic security awareness

    Qualifications aren't the only way to establish this. In fact, real world practical application is more important. If this isn't possible, allocate extra resources for security learning and development.

  • 3

    Make time and resources available for ongoing learning

    Invest in training to develop security knowledge and skills.

  • 4

    Teach developers about the types of threat their code will face

    This goal may be achieved through group workshops that assess attacks and threats to your systems.

  • 5

    Make developers accountable for the security of their code

    Most developers already take pride in their work - security is everyone's concern.

  • 6

    Be aware when there is a particular need to write code defensively

    Take extra time and care when implementing security critical components, writing your code defensively. For example, when validating input which may be attacker-controlled.

  • 7

    Get your security specialists to outline for developers which components are security-critical

     This should not be 'everything.' Developers should know when to seek extra support. Security efforts can then be prioritised.

  • 8

    Use established and well-tested security components instead of creating your own

    Many common problems (eg cryptography and data sanitisation) can be solved using existing solutions. This will save you the time and difficulty of validating your implementation as correct and error-tolerant.

  • 9

    Run sessions to learn from your mistakes, using real issues from your own product where possible

    Provide discussion and feedback on issues to improve future code commits.

  • 10

    Maintain a list of useful security training resources that are relevant for your product

    Developers with access to trusted information are more quickly able to read and apply it. Use trusted sources as working code isn't always robust code.

  • 11

    Limit information available to attackers on public profiles

    Be aware that information published on public profiles can be viewed by an attacker. Job roles, positions and personal details can be used to aid attacks such as spear-phishing.

  • 12

    Keep up to date with security features in the tools, languages and other technologies you use

    Compilers, IDEs and even languages evolve constantly. Often this will mean the addition of new security features, such as memory safe constructs in languages that are not inherently memory safe. But, technologies can also go out of date. In light of this, do not use old, and deprecated APIs.


Published

Reviewed

Version

1.0