Skip to main content
Guidance

Software Security Code of Practice - Implementation Guidance

Helps technology vendors to develop solutions that demonstrate conformance with the Software Security Code of Practice.

Page 3 of 7

Theme 1: Secure design and development

DragonImages via Getty Images

Good security engineering means building technologies that remain usable and resilient throughout their lifetime, even in the face of a cyber attack. Achieving this outcome needs to begin in the design and development phase so that security is ‘baked’ into the software. Ensuring that engineering processes and practices minimise both the likelihood and impact of a security compromise plays an essential part in gaining assurance in vendor competence, and the software they produce.

Developers are not necessarily security experts and the security toolbox available to them can make it hard to navigate cyber security technical complexities, leading to implementation mistakes that could have been avoided. Support to developers can be through access to experts, training, positive security cultures and processes, as well as the availability of up-to-date tools and technology such as use of hardware, compiler and programming language features that make it harder to produce exploitable code. The tools made available to developers should consider usability, ease of maintenance, functionality and cost.  





Published

Reviewed

Version

1.0