SECURITY IN THE SOFTWARE DEVELOPMENT LIFECYCLE
Swati Kaushik, Tanu Mohan · 2014
The purpose of this paper is to help you understand the important role that security plays in the Software Development Life Cycle (SDLC). The paper defines security as it applies to the SDLC and discusses overall SDLC security issues. It then covers each phase of the SDLC and specific security controls and issues for each phase. Note that the SDLC acronym is also used to represent System Development Life Cycle. In many cases, a decision is made to purchase or outsource the software and associated hardware and network systems needed to implement a new application. This is often referred to as the or decision. Buy means you will purchase a finished product from a vendor and means you will hire someone to develop it for you. This paper focuses on the Software Development Life Cycle, but most of the phases, terms, and issues discussed apply to both the buy and build process.