Print

SAFECode guides agile developers in security



Suzanne Kattau
Email
July 23, 2012 —  The Software Assurance Forum for Excellence in Code (SAFECode) last week released “Practical Security Stories and Security Tasks for Agile Development Environments,” a paper that guides agile software developers in secure software development practices.

This new paper provides security-focused stories and security tasks that can easily be integrated into agile-based development environments. The guidance in the paper is not intended to replace security experts, but rather seeks to add a level of self-service for agile developers.

“Because the tasks are translated in a format that agile team members are familiar with, the role of the security expert can take a backseat during development,” Reeny Sondhi, director of product security assurance of the product security office at EMC and one of the authors of the paper, told SD Times in an interview.
Reeny Sondhi
Reeny Sondhi
“Rather than waiting to the very end for some security expert to come do security, this is an attempt to try and bake security in throughout the development life cycle by the developers themselves.”

“Now we are actually putting something on the backlog that a team can come at at the beginning of a sprint—and hopefully most of the sprints—and remove that from the backlog, make sure it gets into what’s called the definition of ‘done’ at the end of the sprint, and then be aware of that and reuse it as necessary during the course of the many sprints,” said Izar Tarandach, principal security engineer of product security at EMC, and one of the authors of the paper. “We are adding basically guidance, assurance and actual tasks that agile developers can perform and keep in mind in a setting that’s familiar to them and one they like to relate to, which are stories and backlog tasks.”

The paper is the outcome of a collaboration of SAFECode members working to simplify the process for addressing security assurance tasks as part of an agile development methodology. SAFECode members that contributed to the paper include Adobe, EMC, Juniper Networks, Microsoft, Nokia, SAP, Siemens and Symantec. SAFECode is an industry-led non-profit organization whose mission is to increase trust in technology products by advancing software assurance methods.




Related Search Term(s): agile, SAFECode, security


Share this link: http://sdt.bz/36820
 

close
NEXT ARTICLE
Cigital Develops Ready-to-Use Tools for Securing the Smart Grid
Cigital Inc. announced the release of the Guide to Developing a Cyber Security and Risk Mitigation Plan Read More...
 
 
 




News on Monday  more>>
Android Developer News  more>>
SharePoint Tech Report  more>>
Big Data TechReport  more>>

   
 
 

 


Download Current Issue
MAY 2013 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
 
 
 

Events calendar tab
5/21/2013 to 5/23/2013
Las Vegas
CTIA

5/28/2013 to 5/31/2013
Boston
BZ Media LLC

5/28/2013 to 5/30/2013
San Francisco
O'Reilly Media

6/2/2013 to 6/7/2013
Las Vegas
SQE

6/2/2013 to 6/6/2013
Orlando
IBM Rational