October 21, 2003

Security Considerations in SDLC

Today I stumbled upon an interesting gem published by NIST this month as Publication 800-64. This paper is entitled Security Considerations in the Information System Development Life Cycle, and is work in which the National Institute of Standard and Technology make recommendations on a framework that incorporates security in all phases of the system development life cycle (SDLC).

I haven't had a chance to completely read through it in depth, but from my first reading it seems well thought out and provides good guidelines for any project that should include security during the early stages of design, rather than later on in the implementation/operational stages of deployment. (Well to be honest, this should ALWAYS be the case anyways, since its much more expensive to bolt on a hacked security solution after the fact)

Happy reading!

Posted by SilverStr at October 21, 2003 10:25 AM | TrackBack