Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers


Many software manufacturers and service providers deploy software and configuration updates as part of their service offerings. These updates may enhance features and/or address security vulnerabilities to provide benefits and security to customers.

However, software and the systems that deploy software are highly complex and continually evolving, making it challenging to deploy secure updates. It is critical for all software manufacturers to implement a safe software deployment program supported by verified processes, including robust testing and measurements. The program should support and enhance both the security and quality of the product and deployment environment. This guide, authored by the Cybersecurity and Infrastructure Security Agency (CISA) and partners, encourages software manufacturers to establish a safe software deployment program as part of their software development lifecycle (SDLC).

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • DoD Studying Implications of Wearable Devices Giving Too Much Info

    January 30, 2018

    Defense Department officials are studying security issues raised by physical conditioning trackers that also can be used to track service members’ whereabouts, a Pentagon spokesman told reporters today. The concern comes from a “heat map” posted by Strava — the makers of a fitness tracking application that shows the routes service members run or cycle in ...

  • Trump’s national security strategy outlines ‘cyberspace’ goals

    December 19, 2017

    President Donald Trump unveiled a national security strategy on Monday that highlights his administration’s “America First” approach to the world and foreign policy. The sprawling 68-page document touches on a number of national security concerns, including economic ties with China and the lethality of the US nuclear arsenal, as well as a brief list of action items that ...

  • America’s 2020 Census systems are a $15bn cyber-security tire fire

    November 1, 2017

    Analysis In 2020, America will run its once-a-decade national census, but the results may not reflect reality if hackers manage to have their way. On Tuesday, the US Senate Homeland Security and Governmental Affairs Committee heard that the 2020 census will be the first to make extensive use of electronic equipment. For example, census workers will be given tablets ...

  • Kaspersky Opens Antivirus Source Code for Independent Review to Rebuild Trust

    October 23, 2017

    Kaspersky Lab — We have nothing to hide! Russia-based Antivirus firm hits back with what it calls a “comprehensive transparency initiative,” to allow independent third-party review of its source code and internal processes to win back the trust of customers and infosec community. Kaspersky launches this initiative days after it was accused of helping, knowingly or unknowingly, Russian government ...

  • How A Drive-by Download Attack Locked Down Entire City for 4 Days

    October 16, 2017

    We don’t really know the pain and cost of a downtime event unless we are directly touched. Be it a flood, electrical failure, ransomware attack or other broad geographic events; we don’t know what it is really like to have to restore IT infrastructure unless we have had to do it ourselves. We look at other people’s ...

  • Kaspersky hearing with House committee set for late October

    October 6, 2017

    In the latest installment of the ongoing saga of Russia-based cybersecurity firm Kaspersky Lab and the U.S. government, the company has a new date with Congress. Rescheduling a hearing originally set for last week, the House Committee on Science, Space and Technology has set a new hearing for October 25, Reuters reports. News of the rescheduled hearing comes a day after ...