Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers


Many software manufacturers and service providers deploy software and configuration updates as part of their service offerings. These updates may enhance features and/or address security vulnerabilities to provide benefits and security to customers.

However, software and the systems that deploy software are highly complex and continually evolving, making it challenging to deploy secure updates. It is critical for all software manufacturers to implement a safe software deployment program supported by verified processes, including robust testing and measurements. The program should support and enhance both the security and quality of the product and deployment environment. This guide, authored by the Cybersecurity and Infrastructure Security Agency (CISA) and partners, encourages software manufacturers to establish a safe software deployment program as part of their software development lifecycle (SDLC).

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • Georgia Unveils Massive Cybersecurity Investment to Protect Against Emerging Threats

    May 23, 2017

    The state of Georgia has set aside $50 million to construct an innovation and training facility that helps state and local agencies better respond to cyber threats. “The Peach State” has more than 30 systems across 16 state agencies that house highly-sensitive financial or public safety information, according to Calvin Rhodes, Georgia’s CIO. The state has ...

  • Korea, US to Begin Joint Investment in and Research on Cyber Security in Late May

    May 22, 2017

    Threats of More intelligent worldwide cyber attacks of these days are strengthening cyber security alliance between Korea and the United States.  According to the Korean Ministry of Science, ICT and Future Planning, the Korean government and the US government (Air Force Research Laboratory) will finalize the selection of a research consortium for the start of joint ...

  • FDA, Industry Look for Gaps in Cybersecurity

    May 18, 2017

    The US Food and Drug Administration (FDA) on Thursday kicked off a fortuitously-timed public workshop on medical device cybersecurity, the agency’s third on the subject to date. At the workshop, FDA officials, representatives from industry and researchers are trying to determine the current gaps in regulatory science as it relates to cybersecurity with the aim of ...

  • Ransomware attack inflames intelligence scrutiny

    May 16, 2017

    The “Wanna Cry” ransomware attack producing global shockwaves has renewed focus on the activities of the National Security Agency (NSA) and how the government decides to disclose cyber vulnerabilities to the private sector. The ransomware campaign, which broke out on Friday and has spread to at least 150 countries and 300,000 machines, is widely believed to ...

  • Donald Trump signs executive order on cybersecurity

    May 13, 2017

    President Donald Trump has signed an executive order to increase the White House’s role in the nation’s cybersecurity. The order assigns responsibility for protecting federal networks and critical infrastructure to the executive branch of government. The executive order declares that the heads of executive departments and agencies are to be held accountable for managing the cybersecurity risk ...

  • NSA Admits They’re Reviewing Government Use of Kaspersky Software

    May 13, 2017

    Kaspersky Lab is stuck in the middle of a rather nasty fight between Washington and Moscow as the Russian-based anti-virus provider is being investigated by the US intelligence agencies. Following news that US officials were more and more concerned about how Russian spies could use Kaspersky’s software to spy on Americans and sabotage US systems, the ...