Skip to main content
Guidance

Secure development and deployment guidance

8 Principles to help you improve and evaluate your development practices, and those of your suppliers

Page 3 of 10

Secure development is everyone's concern

Genuine security benefits can only be realised when delivery teams weave security into their everyday working practices.

This is true even if your organisation has an overall security strategy in place. If security isn’t embedded from the start of the development process, it can become a blocker to implementation.

Effectively embedding security in the development process is likely to require cultural change.

Keep in mind the idea that security is not a destination, but a journey. There is no such thing as perfect security. The aspiration is to have enough security to reduce your risks to a tolerable level.

However, because levels of risk tolerance are variable, you can't rely on tick boxes to tell you when an acceptable level of risk has been reached. Instead, you need to be comfortable with uncertainty, continually assessing whether your defences are sufficient. This process should continue throughout your product's life cycle, iterating as necessary.





Published

Reviewed

Version

1.0