Secure Coding: Building Security into the Software Development Life Cycle
Russell L. Jones, Abhinav Rastogi · Information Systems Security · 2004
Many of the security properties that are outlined repeatedly in the newer regulations and standards can easily be side-stepped. Too often the culprits are unsophisticated software development techniques, a lack of security- focused quality assurance, and scarce security training for software developers, software architects, and project managers. To meet future needs, opportunities, and threats associated with information security, security needs to be “baked in” to the overall systems development life-cycle process.