Introduction to Secure Software Development
Published as Introdução ao Desenvolvimento de Software Seguro
V Mostra de Ensino, Pesquisa e Extensão · online
Abstract
The talk covers the principles and core practices of secure software development, presenting security as a requirement that cuts across the entire software life cycle. It discusses security by design and security by default, risk analysis, threat modelling, input validation, access control and sound dependency management. The material stresses that secure development practices have to be paired with testing, code review and continuous monitoring. The closing argument is that security belongs inside software engineering processes, rather than in reactive approaches based on isolated fixes or late audits.
Keywords: Secure Software Development, Security by Design, Risk Analysis, Threat Modelling, Web Applications, Software Engineering, Security Best Practices, Software Life Cycle, OWASP
Materials
Reference…