Secure Coding

preview_player
Показать описание
Because of limited resources, computer security incident response teams (CSIRTS) are typically unable to respond to the
large number of vulnerabilities reported each year. The goal of the CERT Secure Coding Initiative is to reduce the number of vulnerabilities to a level that can be mitigated fully in DoD operational environments. This will be accomplished by preventing coding errors or discovering and eliminating security flaws during implementation and testing.

CERT has been extremely successful in the development of secure coding standards that have been adopted at corporate levels by companies such as Cisco and Oracle and the development of the Source Code Analysis Laboratory (SCALe) that supports conformance testing of systems against these coding standards. The success of the secure coding standards and SCALe contributed to the impetus for the inclusion of software assurance requirements in the National Defense Authorization Act (NDAA) for Fiscal Year 2013.
Рекомендации по теме