The shared Safe Software Deployment guidance calls software manufacturers to implement safe software development programs supported by verified processes including robust testing, rollout, and feedback loops.
Co-authored by the Cybersecurity and Infrastructure Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC), the Safe Software Deployment guidance directs software manufacturers and cloud-based services to develop robust deployment practices.
The guidance calls for the integration of safe deployment practices throughout the software development life cycle (SDLC), particularly the early stages. It centers on security and risk management at each stage of the SLDC:
The guidance envisions case-by-case applications of deployment safety in SDLCs based on business and customer risk tolerance.
This joint guidance is the latest in CISA’s Secure by Design campaign, which seeks to ensure that customer security is a core business requirement throughout the SDLC and informs cybersecurity best practices.
Authored by Nathan Salminen and Lorea Mendiguren.
Are you sure want to delete comment ?
Scan this QR Code to share this content