- Practical Internet of Things Security
- Brian Russell Drew Van Duren
- 218字
- 2021-06-10 18:42:33
The Secure Development Life Cycle (SDLC)
How security is handled in the development life cycle is frequently a reflection of the industry and its conventional or dictated development methodologies. Some product types, such as aircraft or cars, are simply not amenable to pure Agile development methodologies, because of the complexity and dependencies built into their supply chains, and the absolute nature of the intermediate and final delivery dates of their products.
Regardless, in many cases, development organizations do have some latitude when selecting a development methodology. This section spells out common development approaches and provides guidance on implementing security rigor within those approaches.
When selecting a development methodology, building security in from the beginning means that well-thought-out security, safety, and privacy requirements are elicited, and made traceable throughout the development and update of an IoT device or system. By system, we mean a collection of IoT devices, applications, and services that are integrated to support a business function.
Templated approaches are available that can be applied to any development effort. Microsoft's Security Development Lifecycle (https://www.microsoft.com/en-us/sdl/), for example, incorporates multiple phases: training, requirements, design, implementation, verification, release, and response.
Whichever security life cycle is chosen, it is overlaid on a preferred development approach. Popular methodologies today include waterfall, Spiral, Agile, and DevOps. We discuss each methodology here.
- Learning Python for Forensics
- API攻防:Web API安全指南
- Applied Network Security
- 解密彩虹團隊非凡實戰(zhàn)能力:企業(yè)安全體系建設(shè)(共5冊)
- 安全防御入門手冊
- 黑客攻擊與防范實戰(zhàn)從入門到精通
- 信息組織
- Real-World SRE
- 密碼朋克:自由與互聯(lián)網(wǎng)的未來
- 互聯(lián)網(wǎng)域名國際化與安全技術(shù)導(dǎo)論
- Web前端黑客技術(shù)揭秘
- 大中型網(wǎng)絡(luò)入侵要案直擊與防御
- Web安全之機器學(xué)習(xí)入門
- 網(wǎng)站入侵與腳本技術(shù)快速防殺
- 隱私計算與密碼學(xué)應(yīng)用實踐