Security in the software development lifecycle
How to add security to every phase of the software development lifecycle, with practices from NIST SSDF and OWASP, and the evidence auditors expect.
2 min read
Why security belongs to the whole lifecycle
Most vulnerabilities are introduced during design and coding and found much later. A secure SDLC adds the right activity to each phase, so problems are prevented early and the remaining risk is accepted consciously.
Security activities by phase
| Phase | Activity | Evidence |
|---|---|---|
| Requirements | Security and privacy requirements | Requirements with security criteria |
| Design | Threat modeling | The threat model and its decisions |
| Development | Secure coding and peer review | Approved code reviews |
| Testing | SAST, SCA, DAST and security tests | Scan results and test records |
| Release | A security gate and risk acceptance | A recorded approval |
| Operation | Monitoring and vulnerability management | Patch and incident records |
Frameworks and references
- NIST SP 800-218, the Secure Software Development Framework (SSDF).
- OWASP SAMM, to assess maturity.
- OWASP ASVS, to define verification requirements.
- The OWASP Top 10, for the most common web risks.
- The ISO/IEC 27001 Annex A controls on secure development.
Evidence that matters
Auditors and customers increasingly ask for proof of a secure development process. Keep evidence per change — the review, the tests, the approval — instead of policy documents alone.
How DevGob helps
DevGob enforces the review and approval steps and keeps each change's evidence, so a secure SDLC can be shown, not only described.
Read it in the documentationFrequently asked questions
What is the NIST SSDF?
A set of secure software development practices published by NIST in SP 800-218, grouped into preparing the organization, protecting the software, producing well-secured software and responding to vulnerabilities.
Is a secure SDLC only for regulated companies?
No. Any team that ships software benefits; regulated ones must also be able to prove it.
What is the first step?
Require a peer review of every change and add dependency scanning to the pipeline.
Keep reading
DevOps with governance, on one record
DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.