Vulnerabilities Across the Cycle of Software Build and Use

Understanding vulnerabilities across the entire software life cycle, from design to decommissioning, helps prevent exploitation and improve resilience over time.

2 slides · 1 min read · Domain 8

Slide 1

It stands to reason that if exploitable vulnerabilities in software are caused by errors humans made during the design, coding, test, deployment, and use of that software, then each of these broad phases of activity represent opportunities to reduce the overall threat surface of the in-use system. The system's overall set of requirements creates and represents a threat surface long before it is built or used.

Errors in system requirements can lead to design and build decisions that embed exploitable vulnerabilities into the deployed system.

This is done by failing to build security features into the source code of the system, by failing to adequately test and verify whether security needs are met, or by allowing deployment and in-use errors to erode overall systems security. This offers security professionals an opportunity to strengthen their organization's overall software security posture.

Each step across the cycle of building, deploying, and using software must be supported by policies that provide sufficient governance.

These policies should cover the acquisition or development and use of the organization's software systems, applications, applets, widgets, bots, and other types of software.

Test this domain