This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Software Security 5D Framework"
(2) |
(3) |
||
Line 1: | Line 1: | ||
− | The OWASP Software Security 5D framework represents a practical framework that focus on 5 dimensions to evaluate the maturity of a SDLC. | + | The OWASP Software Security 5D framework represents a practical framework that focus on 5 dimensions to evaluate the maturity of a SDLC and create the best Software Security Roadmap in a fast way.<br> |
− | The key areas are the following: | + | The key areas are the following:<br> |
- SwSec PROCESSES <br> | - SwSec PROCESSES <br> | ||
- SwSec TESTING<br> | - SwSec TESTING<br> |
Revision as of 17:20, 23 October 2018
The OWASP Software Security 5D framework represents a practical framework that focus on 5 dimensions to evaluate the maturity of a SDLC and create the best Software Security Roadmap in a fast way.
The key areas are the following:
- SwSec PROCESSES
- SwSec TESTING
- SwSec TEAM
- SwSec AWARENESS
- SwSec STANDARDS
Traditional Secure SDLC frameworks lack of:
- level of awareness for all the people involved in the process
- description of the application security roles involved
- set of security standards
- security testing tools adopted
This new model aims are:
- build a more practical Secure SDLC for the Companies
- have a fast assessment to undertand the actual maturity of a Company
- create a reliable way to build a concrete Software Security Program