Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers


Many software manufacturers and service providers deploy software and configuration updates as part of their service offerings. These updates may enhance features and/or address security vulnerabilities to provide benefits and security to customers.

However, software and the systems that deploy software are highly complex and continually evolving, making it challenging to deploy secure updates. It is critical for all software manufacturers to implement a safe software deployment program supported by verified processes, including robust testing and measurements. The program should support and enhance both the security and quality of the product and deployment environment. This guide, authored by the Cybersecurity and Infrastructure Security Agency (CISA) and partners, encourages software manufacturers to establish a safe software deployment program as part of their software development lifecycle (SDLC).

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • ​China aims to narrow cyberwarfare gap with US

    August 17, 2018

    China is looking to narrow the gap with the US in terms of cyberwarfare capabilities, according to an assessment of Chinese military capabilities published by the Department of Defense (DoD). The Pentagon report said that in recent years the Chinese army has emphasized the importance of cyberspace for national security because of the country’s increasing reliance on ...

  • US voting systems: Full of holes, loaded with pop music, and ‘hacked’ by an 11-year-old

    August 13, 2018

    DEF CON Hackers of all ages have been investigating America’s voting machine tech, and the results weren’t great. For instance, one 11-year-old apparently managed to hack and alter a simulated Secretary of State election results webpage in 10 minutes. The Vote Hacking Village, one of the most packed-out locations at this year’s DEF CON hacking conference in Las ...

  • DOJ Nab Three FIN7 Cybercrime Suspects in Europe

    August 1, 2018

    Three people believed to be member of the FIN7 (or Carbanak) hacking group have been arrested in Europe, according to the US DOJ. Three suspected members of the FIN7 cybercrime group have been arrested in Europe and accused of hacking more than 120 U.S.-based companies with the intent of stealing bank cards. In total, U.S. Department of ...

  • New Homeland Security Center to Guard Against Cyberattacks

    July 31, 2018

      Homeland Security Secretary Kirstjen Nielsen says the growing cyber threat cannot be underestimated and government and the public must work together to battle it. Nielsen spoke at a cybersecurity summit Tuesday. She announced the creation of the National Risk Management Center at the department. It’s aimed at guarding energy companies, banks and other industries against cyberattacks. ...

  • Pentagon Circulates Software ‘Do Not Buy’ List

    July 30, 2018

    The US Department of Defence has begun circulating a “do not buy” list of software it considers to have Russian and Chinese connections, in the country’s latest tightening of restrictions on foreign tech influence. The Chinese and Russian governments have called previous US restrictions on companies such as Russian security software firm Kaspersky Lab and Chinese telecoms equipment ...

  • No big deal… Kremlin hackers ‘jumped air-gapped networks’ to pwn US power utilities

    July 24, 2018

      The US Department of Homeland Security is once again accusing Russian government hackers of penetrating America’s critical infrastructure. Uncle Sam’s finest reckon Moscow’s agents managed to infiltrate computers networks within US electric utilities – to the point where the miscreants could have virtually pressed the off switch in control rooms, yanked the plug on the Yanks, ...