We've received the following question:
I want to know how to document System Secure Engineering Principles? What is the Content for that?
Answer:
System Secure Engineering Principles refers to the set of security techniques in all architectural layers business, data, applications and technology you are using in your organization. Those principles shall be documented in a policy and regularly reviewed.
As an example you should look on the Software Development LifeCycle phases and define the set of security techniques in each phase:
- Project initiation and planning;
- Functional requirements definition;
- Systems design specifications;
- Build (develop) and document
- Acceptance
- Transition to production (instalation)
These set of considerations shall also be applied to outsourcers where applicable, using contracts and other binding agreements between parties.
Hope it helps
There are code of best practices for each programming language. Java for example has a code of best practices that you can download from the official page of ORACLE. So, depending on the language, you can follow a specific code of best practices.
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.