CyberTRIZPEDIA

NIST SSDF

Recommended secure software development practices from NIST.

Jurisdiction
International / Framework
Issuer
National Institute of Standards and Technology
Effective
2020-04-23

Sectors

IT & CybersecurityTechnologyDigital Infrastructure

Articles (70)

Governance and Accountability — ApplicabilityIntroductionRisk Management Measures — GovernanceDefine Security Requirements for Software DevelopmentIncident Reporting and Escalation — Process RequirementsIdentify and document security requirements for software development infrastructures and processesSupply Chain and Third Parties — Evidence and RecordsIdentify and document security requirements for organization-developed softwareResilience Testing and Improvement — Testing and AssuranceCommunicate requirements to all third parties who will provide commercial software componentsGovernance and Accountability — ReportingImplement Roles and ResponsibilitiesRisk Management Measures — RemediationCreate new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLCIncident Reporting and Escalation — Third-Party ControlsProvide role-based training for all personnel with responsibilities that contribute to secure developmentSupply Chain and Third Parties — TrainingObtain upper management or authorizing official commitment to secure developmentResilience Testing and Improvement — Management ReviewImplement Supporting ToolchainsSpecify which tools or tool types must or should be included in each toolchainFollow recommended security practices to deploy, operate, and maintain tools and toolchainsConfigure tools to generate artifacts of their support of secure software development practices.Define and Use Criteria for Software Security ChecksDefine criteria for software security checks and track throughout the SDLC.Implement processes, mechanisms, etc. to gather and safeguard the necessary information in support of the criteria.Implement and Maintain Secure Environments for Software DevelopmentSeparate and protect each environment involved in software development.Secure and harden development endpoints to perform development-related tasks using a risk-based approach.Protect All Forms of Code from Unauthorized Access and TamperingStore all forms of code based on the principle of least privilege so that only authorized personnel, tools, services, etc. have access.Provide a Mechanism for Verifying Software Release IntegrityMake Software Integrity Verification Information Available to AcquirersArchive and Protect Each Software ReleaseSecurely Archive Necessary Files and Supporting Data for Each ReleaseCollect, Safeguard, Maintain, and Share Provenance Data for All ComponentsDesign Software to Meet Security Requirements and Mitigate Security RisksUse Forms of Risk Modeling to Assess Security RiskTrack and Maintain Software Security Requirements, Risks, and Design DecisionsBuild in Support for Standardized Security Features and ServicesReview the Software Design to Verify Compliance with Security Requirements and Risk InformationHave Qualified Persons or Automated Processes Review Software DesignVerify Third-Party Software Complies with Security Requirements (Moved)Reuse Existing, Well-Secured Software When Feasible Instead of Duplicating FunctionalityAcquire and Maintain Well-Secured Software Components from Third PartiesCreate and Maintain Well-Secured Software Components In-HouseVerify Third-Party Software Components Comply with Requirements Throughout Their Life CyclesCreate Source Code by Adhering to Secure Coding PracticesFollow Secure Coding Practices Appropriate to Development Languages and EnvironmentConfigure the Compilation, Interpreter, and Build Processes to Improve Executable SecurityUse Compiler, Interpreter, and Build Tools That Offer Features to Improve Executable SecurityDetermine, Implement, and Use Approved Compiler and Build Tool ConfigurationsReview and/or Analyze Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security RequirementsDetermine whether code review and/or code analysis should be usedPerform code review and/or code analysis based on secure coding standardsTest Executable Code to Identify Vulnerabilities and Verify Compliance with Security RequirementsDetermine whether executable code testing should be performed and which typesScope, design, perform, and document executable code testingConfigure Software to Have Secure Settings by DefaultDefine a secure baseline for default settingsImplement and document the default settingsGather and Investigate Vulnerability ReportsReview and Test Code for VulnerabilitiesEstablish Vulnerability Disclosure and Remediation PolicyAnalyze Vulnerabilities to Plan RemediationPlan and Implement Risk Responses for VulnerabilitiesAnalyze Vulnerabilities for Root CausesIdentify Patterns in Root Causes Over TimeEradicate Classes of VulnerabilitiesUpdate SDLC Process to Prevent Root Cause Recurrence