Advances in computer technology have prompted the development of frameworks that address security and user requirements in the software development lifecycle. This article examines several established ...
This white paper recommends a core set of high-level secure software development practices, called a secure software development framework (SSDF), to be added to each software development life cycle ...
The term Secure Product Development Framework (SPDF) was introduced by FDA in the draft guidance "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions" ...
Software security may finally be getting the attention it deserves as more countries institute necessary guidelines. But with threats increasing against the software supply chains, it is too soon to ...
In an era of evolving and accelerating cyberthreats, many C-suite leaders grapple with the complexities of scaling their security strategies to meet the ever-increasing demand for software products, ...
On January 23, 2026, the Office of Management and Budget (OMB) reversed some relatively new requirements for secure software development that had been imposed on federal contractors. This move is ...
The White House's Office of Management and Budget (OMB) has issued a memorandum to roll back software security requirements established by the previous administration, including following NIST ...
On June 6, 2025, President Trump issued an Executive Order entitled “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144” ...
For all the scary talk about cyberattacks from vendors and industry experts, relatively few attacks are actually devastating. But the Jaguar Land Rover (JLR) attack was. The JLR breach wasn’t some ...
Supply chain security continues to receive critical focus in the realm of cybersecurity, and with good reason: incidents such as SolarWinds, Log4j, Microsoft, and Okta software supply chain attacks ...
Applications are now a primary target for threat actors, yet many organizations still rely on traditional secure software development lifecycles (SSDLCs) that limit their ability to respond to ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results