Software Acquisition via Third-Party Development

Managing third-party software acquisition carefully ensures purchased products meet security requirements, avoid hidden vulnerabilities, and remain free or malicious code.

2 slides · 1 min read · Domain 8

Slide 1

The organization contracting for a third party to develop new software systems, customize existing ones in use by that organization, or tailor commercial software platforms to suit the organization's needs has an opportunity to ensure that the acquisition process includes appropriate software assurance measures.

This acquisition process can be leveraged to promote good software development practices and facilitate the delivery of trustworthy software to the organization. The nature of the contract between the parties should reflect to the degree to which the development, test, acceptance test, and security or software assurance activities are open-ended or fixed. (One can argue that since few software projects are ever delivered on time, within budget, and with all requirements satisfied, such a fixed contracting baseline may be overly optimistic.) As always, security should be an integral part of every stage of the software development life cycle, from planning and design to implementation, testing, and deployment.

Many software and systems developers use Capability Maturity Model Integration (CMMI) to guide process improvement and assess capabilities, especially related to applications development. However, core CMMI practices may not explicitly address safety and security. As such, suppliers claiming mature process capabilities can fail to exercise practices critical to software assurance. Therefore, the security professional should verify whether software assurance has been factored into suppliers' process capabilities enough to protect their organization's risk mitigation needs.

Test this domain