Presentation is loading. Please wait.

Presentation is loading. Please wait.

Software Development Security Chapter 10 Part 3 Pages 1108 to 1125.

Similar presentations


Presentation on theme: "Software Development Security Chapter 10 Part 3 Pages 1108 to 1125."— Presentation transcript:

1 Software Development Security Chapter 10 Part 3 Pages 1108 to 1125

2 Software Security Best Practices Web Application Security Consortium (WASC) – Best security practices for the WWW – Figure 10-8 on page 1109 Open Web Application Security Project (OWASP) – https://www.owasp.org/index.php/Main_Page https://www.owasp.org/index.php/Main_Page – Top 10 2013

3 Software Security Best Practices Build Security In (BSI) – Department of Homeland Security – Best practices, guidelines, rules, principles Common Weakness Evaluation (CWE) – http://cwe.mitre.org/ http://cwe.mitre.org/ – Top 25 ISO/IEC 27034 Standard – Framework, application security management

4 Software Development Models Build and Fix – Little or no planning – Get the product out the door as fast as possible – Problems are dealt with when they occur – Not really a formal SDLC model Waterfall Model – Figure 10-9 on Page 1112

5 Software Development Models V-shaped model – Figure 10-10 on page 1113

6 Prototyping Rapid Prototyping – Build a prototype to test understanding – Is it feasible – User testing Evolutionary Prototypes – Incremental improvements – Evolves into the final product

7 Prototyping Operational Prototype – Implement in production environment – Update as customer feedback is gathered

8 Incremental Model Figure 10-11 on page 1115

9 Spiral Model Risk analysis Figure 10-12 on page 1116

10 RAD Rapid Application Development – Uses rapid prototyping instead of extensive upfront planning. – Accelerates the development process – Figure 10-13 on page 1117 Agile – Customer collaboration – More flexible and adaptable than Waterfall

11 CMMI Capability Maturity Model Integration Carnegie Mellon University Software Engineering Institute Figure on page 1121 Even Agile Compare vendors

12 Change Control Control changes to documentation, software, tests Roll back changes Who make the change Approval Multiple versions Software Configuration Management


Download ppt "Software Development Security Chapter 10 Part 3 Pages 1108 to 1125."

Similar presentations


Ads by Google