Security in the software development lifecycle

How to add security to every phase of the software development lifecycle, with practices from NIST SSDF and OWASP, and the evidence auditors expect.

2 min read

Why security belongs to the whole lifecycle

Most vulnerabilities are introduced during design and coding and found much later. A secure SDLC adds the right activity to each phase, so problems are prevented early and the remaining risk is accepted consciously.

Security activities by phase

Security activities and evidence in each phase
Phase Activity Evidence
Requirements Security and privacy requirements Requirements with security criteria
Design Threat modeling The threat model and its decisions
Development Secure coding and peer review Approved code reviews
Testing SAST, SCA, DAST and security tests Scan results and test records
Release A security gate and risk acceptance A recorded approval
Operation Monitoring and vulnerability management Patch and incident records

Frameworks and references

  • NIST SP 800-218, the Secure Software Development Framework (SSDF).
  • OWASP SAMM, to assess maturity.
  • OWASP ASVS, to define verification requirements.
  • The OWASP Top 10, for the most common web risks.
  • The ISO/IEC 27001 Annex A controls on secure development.

Evidence that matters

Auditors and customers increasingly ask for proof of a secure development process. Keep evidence per change — the review, the tests, the approval — instead of policy documents alone.

How DevGob helps

DevGob enforces the review and approval steps and keeps each change's evidence, so a secure SDLC can be shown, not only described.

Read it in the documentation

Frequently asked questions

What is the NIST SSDF?

A set of secure software development practices published by NIST in SP 800-218, grouped into preparing the organization, protecting the software, producing well-secured software and responding to vulnerabilities.

Is a secure SDLC only for regulated companies?

No. Any team that ships software benefits; regulated ones must also be able to prove it.

What is the first step?

Require a peer review of every change and add dependency scanning to the pipeline.

DevOps with governance, on one record

DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.