Skip to main content
Guidance

Software Security Code of Practice - Implementation Guidance

Helps technology vendors to develop solutions that demonstrate conformance with the Software Security Code of Practice.

Page 4 of 7

Theme 2: Build environment security

The build environment is an enticing prospect for attackers. The build environment is typically where code is compiled, built, and packaged into a deployable form. This would ideally be a different environment from a development environment where developers would write and test their code before pushing that through to a build environment. Security in the build environment includes tools such as build servers, compilers, internal repositories, and data such as configurations and metadata.

Securing the build environment will not only mitigate loss of service and data exfiltration, but will also help secure the supply chain by reducing the risk that something within the build environment has been compromised (and then further distributed to customers).




Published

Reviewed

Version

1.0