Skip to main content
Guidance

Software Security Code of Practice - Implementation Guidance

Helps technology vendors to develop solutions that demonstrate conformance with the Software Security Code of Practice.

Page 5 of 7

Theme 3: Secure deployment and maintenance

AndreyPopov via Getty Images

A secure deployment and maintenance strategy will reduce the likelihood of vulnerabilities being introduced into software, both during initial distribution and then through the supply of subsequent patches and updates through its supported lifetime.

You may choose to roll out the software to a select group initially to minimise any remedial action should a post-release issue be found. For instance you might first trial an internal rollout with a small group. Other approaches include A/B testing, where data-driven decisions can be made based on user feedback. This can work equally well for security aspects and features of the software.

No software will remain bug-free throughout its lifetime. Having internal and external processes in place to identify, triage and manage vulnerabilities is a central part of ensuring software remains resilient throughout its lifetime.






Published

Reviewed

Version

1.0