Software Security Code of Practice - Implementation Guidance
Pages
Page 7 of 7
Appendix 1: Secure development frameworks
There are many secure development frameworks available ‘off-the-shelf’. Examples include:
NIST Secure Software Development Framework
A set of fundamental, sound and secure software development practices based on established secure software development practice documents from organizations such as BSA, OWASP, and SAFECode.
Microsoft Security Development Lifecycle
The approach Microsoft uses to integrate security into DevOps processes (sometimes called a DevSecOps approach).
OWASP Software Development Lifecycle
The OWASP® Foundation works to improve the security of software through its community-led open source software projects.
Cisco Secure Development Lifecycle
Designed to introduce security and privacy throughout the development process.
Supply-Chain Levels for Software Artifacts (SLSA)
Supply-chain Levels for Software Artifacts, or SLSA ('salsa') is a security framework, a checklist of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure.
S2C2F Simplified Requirements
The core concepts of the Secure Supply Chain Consumption Framework (S2C2F) to outline and define how to securely consume OSS dependencies (such as NuGet and NPM) into the developer's workflow.