Software Assurance Pocket Guides
The series of pocket guides by the US Department of Homeland Security National Cyber Security Division's Software Assurance (SwA) community has been extended by the addition of three updated documents.
Secure Coding (v1.1) and Software Assurance in Education, Training and Certification (v2.1) and Architecture and Design Considerations for Secure Software (v1.3) have been added to the range which now includes:
- SwA in Acquisition and Outsourcing
- Software Assurance in Acquisition and Contract Language
- Software Supply Chain Risk Management and Due Diligence
- SwA in Development
- Key Practices for Mitigating the Most Egregious Exploitable Software Weaknesses
- Software Security Testing
- Requirements and Analysis for Secure Software
- Architecture and Design Considerations for Secure Software
- Secure Coding
- SwA Life Cycle
- Software Assurance in Education, Training & Certification
I must admit I had to check the precise meaning of "egregious" (outstandingly bad, flagrant; or distinguished, eminent). There are almost a dozen more guides in the pipeline. These are indespensable references, and free to download. If you have comments or suggestions, please provide feedback to the SwA forum.
Posted on: 04 March 2011 at 07:24 hrs

Comments are filtered automatically and should appear shortly after they been checked.