全网唯一标准王
文库搜索
切换导航
文件分类
频道
联系我们
问题反馈
文件分类
联系我们
问题反馈
批量下载
Fundamental Practices for Secure Software Development Third Edition March 2018 c . 5 b u Essential Elements of a Secure Development Lifecycle Program h t i g © 2018 SAFECode – All Rights Reserved. m o Fundamental Practices for Secure Software Development Table of Contents Executive Summary .................................................................................................................................... 4 Introduction ................................................................................................................................................. 5 Audience ................................................................................................................................................. 5 SAFECode Guidance and Software Assurance Programs ..................................................................... 6 Application Security Control Definition .................................................................................................... 7 Actively Manage Application Security Controls ...................................................................................... 7 m o Design .......................................................................................................................................................... 9 Secure Design Principles ....................................................................................................................... 9 c . 5 Threat Modeling .................................................................................................................................... 10 Develop an Encryption Strategy ........................................................................................................... 11 Standardize Identity and Access Management .................................................................................... 12 b u Establish Log Requirements and Audit Practices ................................................................................ 14 Secure Coding Practices .......................................................................................................................... 15 h t i g Establish Coding Standards and Conventions ..................................................................................... 15 Use Safe Functions Only ...................................................................................................................... 15 Use Code Analysis Tools To Find Security Issues Early ..................................................................... 17 Handle Data Safely ............................................................................................................................... 17 Handle Errors........................................................................................................................................ 20 Manage Security Risk Inherent in the Use of Third-party Components .............................................. 21 Testing and Validation .............................................................................................................................. 22 Automated Testing ............................................................................................................................... 22 Manual Testing ..................................................................................................................................... 24 Manage Security Findings........................................................................................................................ 27 Define Severity ..................................................................................................................................... 27 Risk Acceptance Process ..................................................................................................................... 28 Vulnerability Response and Disclosure ................................................................................................. 29 Define Internal and External Policies ................................................................................................... 29 Define Roles and Responsibilities ........................................................................................................ 29 Ensure that Vulnerability Reporters Know Whom to Contact ............................................................... 30 Manage Vulnerability Reporter
SAFECode_Fundamental_Practices_for_Secure_Software_Development_March_2018 (SAFECode 安全软件开发基本实践)
文档预览
英文文档
38 页
50 下载
1000 浏览
0 评论
0 收藏
3.0分
赞助2元下载(无需注册)
温馨提示:本文档共38页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
下载文档到电脑,方便使用
赞助2元下载
本文档由 路人甲 于
2022-05-30 11:53:07
上传分享
举报
下载
原文档
(762.2 KB)
分享
友情链接
GB-T 20037-2005 纺织机械 染整机器 左右侧定义.pdf
GB-T 22191-2008 船舶电气设备 设备 灯具和附件.pdf
GB 8058-2003 陶瓷烹调器铅、镉溶出量允许极限和检测方法.pdf
GB-T 682-2002 化学试剂 三氯甲烷.pdf
GB-T 32868-2016 纳米技术 单壁碳纳米管的热重表征方法.pdf
GB-T 18590-2001 金属和合金的腐蚀 点蚀评定方法.pdf
GB-T 30213-2013 飞机 液压附件 识别附件所适用液压油的标志.pdf
GB-Z 43468.1-2023 残障人辅助技术系统和辅助器具 轮椅车系固和乘坐者约束系统 第1部分 一般要求和试验方法.pdf
GB-T 29732-2021 表面化学分析 中等分辨俄歇电子能谱仪 元素分析用能量标校准.pdf
GB-T 5717-2013 纺织品 色牢度试验 耐水斑色牢度.pdf
GB-T 44082-2024 道路车辆 汽车列车多车辆间连接装置 强度要求.pdf
GB-T 15212-1994 广播及类似声系统用连接器的应用.pdf
GB-T 20863.4-2007 起重机械 分级 第4部分 臂架起重机.pdf
GB-T 15273.1-1994 信息处理 八位单字节编码图形字符集 第一部分 拉丁字母一.pdf
GB-T 27939-2011 滑动轴承 几何和材料质量特性的质量控制技术和检验.pdf
GB-T 18697-2002 声学 汽车车内噪声测量方法.pdf
GB-T 18007-2011 咖啡及其制品 术语.pdf
GB-T 38179-2019 燃气轮机应用 用于发电设备的要求.pdf
GB-T 33487-2017 船舶与海上技术 船舶下水用气囊.pdf
GB-T 22352-2008 土方机械 吊管机 术语和商业规格.pdf
1
/
3
38
评价文档
赞助2元 点击下载(762.2 KB)
回到顶部
×
微信扫码支付
2
元 自动下载
官方客服微信:siduwenku
支付 完成后 如未跳转 点击这里 下载
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们
微信(点击查看客服)
,我们将及时删除相关资源。