Software Security Code of Practice - Implementation Guidance
Pages
Page 2 of 7
About the Software Security Code of Practice
Software is the lifeblood of the digital economy. It underpins all the digital services we rely on, driving productivity and growth across the UK. As attacks on software proliferate, improving the security of software supply chains is a crucial step to improving the resilience of organisations and systems.
The Software Security Code of Practice outlines the fundamental security and resilience principles expected of all organisations that develop and/or sell software. Alongside the Code of Practice we have included this guidance and some Assurance Principles and Claims (APCs) which includes a set of suggested claims that outline the steps that vendors could take to ensure their software meets these principles, and thus have basic resilience against cyber attacks.
The claims are outcome-based (rather than prescriptive measures), giving organisations the flexibility to implement security solutions appropriate for their software. The document you are now reading describes how one might implement solutions to most easily evidence the claims.
Note:
The principles are objective measures that must be evidenced to provide confidence in the resilience of the software against an attacker that:
- is operating remotely
- has access to publicly available tools
- has minimal resources
That is, meeting these principles (and claims) will not be sufficient to protect against a sophisticated and highly motivated attacker. However, they will protect against the most common attacks on software.
As with all cyber security matters, building resilience is a risk management process where decisions will need to be taken and trade-offs made. We expect vendors to implement this guidance in accordance with their own risk management processes and governance. The Cyber Governance Code of Practice sets out the critical governance areas board members need to tackle in order to protect their organisation.
Further reading
Secure by design
The UK government uses the term ‘secure by design’ to describe a development approach that encourages organisations to ‘bake' cyber security into all stages of the product life cycle, rather than adding it as an afterthought. Doing this addresses cyber security problems at their root cause and prevents costly redesigns later on.
The importance of this concept is recognised internationally and endorsed by the United States Cybersecurity and Infrastructure Security Agency (CISA) 'Secure by Design' initiative.
Vendors of software that are secure by design:
- do not charge extra for implementing essential security functionality
- make it as frictionless as possible to configure software so it operates securely
- create great software with the appropriate security as standard, without people having to turn it on (or even knowing it’s there)
If this ‘secure by default’ approach is not possible, the user should be provided with guidance on how to securely configure the software .
Gaining assurance
Depending on the level of confidence required by the customer, users can gain confidence that they are buying software with basic cyber resilience (that will continue to provide security throughout its lifetime) through self-assessment, audit, or independent testing.
- Vendors can use self-assessment against the Code of Practice using the Assurance Principles and Claims document.
- For audit and independent testing through industry, please refer to the Cyber Resilience Testing Facilities website.