This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Security Integration System"
From OWASP
MB netblue4 (talk | contribs) (→Client specific architectural requirements) |
MB netblue4 (talk | contribs) |
||
Line 47: | Line 47: | ||
<h1><b>See how developers use SCAT</b></h1> | <h1><b>See how developers use SCAT</b></h1> | ||
See below how the Secure code assurance tool integrates security into software development phases | See below how the Secure code assurance tool integrates security into software development phases | ||
− | + | ||
==Sprint planning phase == | ==Sprint planning phase == | ||
<b>Objective</b>: Ensures security requirements are understood <br> | <b>Objective</b>: Ensures security requirements are understood <br> | ||
Line 67: | Line 67: | ||
</ul> | </ul> | ||
− | == | + | == Development phase == |
<b>Objective</b>: Ensure correct implementation of security requirements<br> | <b>Objective</b>: Ensure correct implementation of security requirements<br> | ||
Line 83: | Line 83: | ||
</ul> | </ul> | ||
− | == | + | == Secure code review phase == |
<b>Objective</b>: Ensure correct implementation of security requirements<br> | <b>Objective</b>: Ensure correct implementation of security requirements<br> | ||
Line 97: | Line 97: | ||
</ul> | </ul> | ||
− | == | + | == Testing phase== |
<b>Objective</b>: Ensure valid security testing<br> | <b>Objective</b>: Ensure valid security testing<br> | ||
Line 109: | Line 109: | ||
</li> | </li> | ||
</ul> | </ul> | ||
− | == | + | == Approval phase == |
<b>Objective</b>: Streamline the approval and audit process<br> | <b>Objective</b>: Streamline the approval and audit process<br> | ||
Line 122: | Line 122: | ||
</li> | </li> | ||
</ul> | </ul> | ||
− | == | + | == Risk management == |
<b>Objective</b>: Enable risk managers to prioritise, plan and monitor mitigation efforts<br> | <b>Objective</b>: Enable risk managers to prioritise, plan and monitor mitigation efforts<br> | ||
Revision as of 11:25, 30 September 2019
|