Skip to main content
Guidance

Software Security Code of Practice - Implementation Guidance

Helps technology vendors to develop solutions that demonstrate conformance with the Software Security Code of Practice.

Page 7 of 7

Appendix 1: Secure development frameworks

Laurence Dutton via Getty Images

There are many secure development frameworks available ‘off-the-shelf’. Examples include:

NIST Secure Software Development Framework
A set of fundamental, sound and secure software development practices based on established secure software development practice documents from organizations such as BSA, OWASP, and SAFECode.

Microsoft Security Development Lifecycle
The approach Microsoft uses to integrate security into DevOps processes (sometimes called a DevSecOps approach).

OWASP Software Development Lifecycle
The OWASP® Foundation works to improve the security of software through its community-led open source software projects.

Cisco Secure Development Lifecycle
Designed to introduce security and privacy throughout the development process.

Supply-Chain Levels for Software Artifacts (SLSA)
Supply-chain Levels for Software Artifacts, or SLSA ('salsa') is a security framework, a checklist of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure.

S2C2F Simplified Requirements
The core concepts of the Secure Supply Chain Consumption Framework (S2C2F) to outline and define how to securely consume OSS dependencies (such as NuGet and NPM) into the developer's workflow.

Published

Reviewed

Version

1.0