
When security practitioners attempt to introduce secure development practices into a development process and organization they are less than accepted. This is because Development organizations reject formal internal structure and process imposed from the outside except begrudgingly when things have gone wrong.
This e-book explores how to implement secure development practices in a development organization. The topics touched upon in this e-book are:
- Three approaches to consider
- An application security advocate must lead the way
- Collecting key risk and performance metrics
- Ways to build in security
- How to best analyze source code
- And more