Information protection is becoming a focal point for designing, creating and implementing software applications within highly integrated technology environments. The use of a safe coding technique in the software development process is required by many industrial IT security standards and policies. Despite current cyber protection measures and best practices, vulnerabilities still remain strong and become a huge threat to every developed software. It is crucial to understand the position of secure software development for security management, which is affected by causes such as human security-related factors. Although developers are often held accountable for security vulnerabilities, in reality, many problems often grow from a lack of organizational support during development tasks to handle security. While abstract safe coding guidelines are generally recognized, there are limited low-level secure coding guidelines for various programming languages. A good technique is required to standardize these guidelines for software developers. The goal of this paper is to address this gap by providing software designers and developers with direction by identifying a set of secure software development guidelines. Additionally, an overview of criteria for selection of safe coding guidelines is performed along with investigation of appropriate awareness methods for secure coding.
翻译:虽然许多工业信息技术安全标准和政策要求在软件开发过程中使用安全编码技术,但目前的网络保护措施和最佳做法仍然很薄弱,对每一个开发的软件都构成巨大威胁。至关重要的是,要了解安全管理安全软件开发的定位,因为安全管理受人的安全相关因素等原因的影响。虽然开发商往往对安全弱点负责,但事实上,许多问题往往由于发展任务期间缺乏组织支持而增加。虽然普遍认识到安全编码准则的抽象性,但各种编译语言的低级别编码指南有限。需要一种良好的技术使软件开发商的这些指南标准化。本文件的目标是通过确定一套安全软件开发准则,向软件设计者和开发商提供指导,从而弥补这一差距。此外,在调查安全编码的适当意识方法的同时,还对安全编码准则的选择标准进行了概述。