Skip to main content
Guidance

Software Security Code of Practice - Implementation Guidance

Helps technology vendors to develop solutions that demonstrate conformance with the Software Security Code of Practice.

Page 2 of 7

About the Software Security Code of Practice

pixdeluxe via Getty Images

Software is the lifeblood of the digital economy. It underpins all the digital services we rely on, driving productivity and growth across the UK. As attacks on software proliferate, improving the security of software supply chains is a crucial step to improving the resilience of organisations and systems.

The Software Security Code of Practice outlines the fundamental security and resilience principles expected of all organisations that develop and/or sell software. Alongside the Code of Practice we have included this guidance and some Assurance Principles and Claims (APCs) which includes a set of suggested claims that outline the steps that vendors could take to ensure their software meets these principles, and thus have basic resilience against cyber attacks.

The claims are outcome-based (rather than prescriptive measures), giving organisations the flexibility to implement security solutions appropriate for their software. The document you are now reading describes how one might implement solutions to most easily evidence the claims.  

Note:

The principles are objective measures that must be evidenced to provide confidence in the resilience of the software against an attacker that:

  • is operating remotely 
  • has access to publicly available tools 
  • has minimal resources

That is, meeting these principles (and claims) will not be sufficient to protect against a sophisticated and highly motivated attacker. However, they will protect against the most common attacks on software.

As with all cyber security matters, building resilience is a risk management process where decisions will need to be taken and trade-offs made. We expect vendors to implement this guidance in accordance with their own risk management processes and governance. The Cyber Governance Code of Practice sets out the critical governance areas board members need to tackle in order to protect their organisation.

Further reading

 



Published

Reviewed

Version

1.0