« Importance of documenting requirements | Main | How important is this? »

Importance of security in the SDLC

David Lacey mentions the importance of embedding security into the SDLC in his blog . It's a view I completely support and frequently see the positive impact on risk status between those products with an embedded process and those that don't.

Implementing embedded security within the SDLC does not have to be a complex process. In fact, quite the opposite in my opinion. Making the process simple and transparent is the key to success but getting acceptance within large development groups, used to operating in a particular way, is never going to be easy.

The best technical resource that I would recommend is "The Security Development Lifecycle" by M Howard. You can buy it here on Amazon.

But as usual it comes down to how well you can communicate the benefits. Just about every developer and manager I talk to is open to the concept but in practice the pressures of delivery and costs are seen as being overwhelming. So my advice is to set small, achievable objectives rather than to try to rush headlong into a new all-encompassing process. It's working for me here.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/1260

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on January 3, 2007 9:01 AM.

The previous post in this blog was Importance of documenting requirements.

The next post in this blog is How important is this?.

Many more can be found on the main index page or by looking through the archives.