SAFECode Blog

About Our Blog

SAFECode is a global, industry-led effort to identify and promote best practices for developing and delivering more secure and reliable software, hardware and services. We created this blog so that we could keep you posted on new developments in software assurance and our ongoing work in this area.

Please note that the opinions expressed in this blog are those of the writer or contributor and do not necessarily reflect the opinions of SAFECode or its member companies.

By Steve Lipner, Executive Director, SAFECode.

Today, we joined the Cloud Security Alliance (CSA) in releasing a new framework for thinking about DevSecOps in a cloud environment. The paper, “The Six Pillars of DevSecOps: Achieving Reflexive Security through Integration of Security, Development and Operations,” defines six focus areas critical to implementing and integrating DevSecOps into an organization.

READ MORE

By Steve Lipner, Executive Director, SAFECode.

Recruiting developers and testers from the product group is a great way to build a top-notch application security team. Here’s why.

READ MORE

By Steve Lipner, SAFECode Executive Director This week, the Business Software Alliance released The BSA Framework for Software Security. The document aims to provide a consolidated framework that brings together best practices in a manner that can be effectively described and communicated, regardless of the development environment or the purpose of the software. Specifically, according […]

READ MORE

By: Stacy Simpson, SAFECode

A key principle guiding SAFECode’s work has always been our belief that secure software development can only be achieved with an organizational commitment and a holistic assurance process. But what does that mean in practice?

READ MORE

By: Stacy Simpson, SAFECode

A key principle guiding SAFECode’s work has always been our belief that secure software development can only be achieved with an organizational commitment and a holistic assurance process. But what does that mean in practice?

READ MORE

By: Stacy Simpson, SAFECode

Next week, tens of thousands of security professionals will gather once again in San Francisco to talk all things security, including software security. At SAFECode, this is one of our favorite times of the year, despite the fact that many might not know we are even there.

READ MORE

By Vishal Asthana, Security Compass (former) with Altaz Valani, Security Compass

Ever wonder what it is like to work on a SAFECode project team? Two of our Champions – Vishal Asthana and Altaz Valani were kind enough to participate in a short Q&A; about their experience working on the Security Champions and other SAFECode projects.

READ MORE

This is the closing post to our Security Champions Series. Read all of the posts below. Part One: Start 2019 Strong: Join SAFECode for Our Month of Champions Part Two: Building Secure Software: It Takes a Champion Part Three: Putting a Face to Software SCs Part Four: How to Build an Effective Security Champions Program […]

READ MORE

Security Champions Podcast: Final Thoughts

Hosted by John Martin, Boeing. Featuring Tania Ward, Dell and Nick Ozmore, Veracode

As the Month of Champions comes to an end, join the Security Champions Team as they offer some parting advice on developing a successful Security Champions program.

READ MORE

Part One: Start 2019 Strong: Join SAFECode for Our Month of Champions Part Two: Building Secure Software: It Takes a Champion Part Three: Putting a Face to Software SCs Part Four: How to Build an Effective Security Champions Program Part Five: Warning: Six Signs Your Security Champions Program is in Trouble Part Six: Kicking off […]

READ MORE

Copyright © 2007- Software Assurance Forum for Excellence in Code (SAFECode) – All Rights Reserved
Privacy Policy

Share
Share