Selected Talks

2021Oral presentationPortuguese

Introduction to Secure Software Development

Published as Introdução ao Desenvolvimento de Software Seguro

V Mostra de Ensino, Pesquisa e Extensão · online

Abstract

The talk covers the principles and core practices of secure software development, presenting security as a requirement that cuts across the entire software life cycle. It discusses security by design and security by default, risk analysis, threat modelling, input validation, access control and sound dependency management. The material stresses that secure development practices have to be paired with testing, code review and continuous monitoring. The closing argument is that security belongs inside software engineering processes, rather than in reactive approaches based on isolated fixes or late audits.

Materials

Reference