Software Assurance and Security Assessment
Application software has become an integral component in every organization over the last number of decades, and building better applications that have the proper security controls built-in based on requirements becomes very important.
4 slides · 1 min read · Domain 8
As part of this importance, organizations need to evaluate the effectiveness of the applications development process, including how security is involved and ultimately that the security designed into the application is indeed effective based on the organization's requirements.
Fundamentally, this is applied software risk management, with emphasis on the ongoing assessment of the successful operation of the chosen risk controls.
As with all risk management and mitigation processes, this is applied across the entire systems lifecycle, from conception through development, deployment, operational support and retirement or disposal at the end of the system's useful life. Meaningful indicators must be established and used throughout these assessment processes, not only to provide real-time incident detection and warning, but also as the basis of analysis and evaluation of the chosen risk controls.
Borrowing from similar portrayals of the stages of risk management frameworks suggests that each action taken by one part of the organization, as it plans and accomplishes security or risk mitigation activities, has a strong relationship with decisions and actions that other elements in the organization are responsible for.
Text on this slide
Ongoing Assessment
Risk Controls
Planning
Systems/ Process Quality
Security Needs
Risk Assessment
Changes to business and mission needs may drive many changes to risk assessment, and therefore risk controls, in a top- down fashion; while at the same time, results from ongoing security assessments may suggest the needs for changes in security policies such as information classification or access authorization guidelines. Rather than a virtuous circle, in which each step of a process reinforces and strengthens the next, this is more of a virtuous cloud or network of activities and their interrelationships.
