Skip to content

Secure SDLC

A Secure SDLC integrates security across the whole development lifecycle, instead of leaving it as an audit at the end. The principle is shift-left: the earlier a flaw is found, the cheaper it is to fix — a design bug in production costs orders of magnitude more than in the requirements phase.

Cost to fix a flaw: requirements < design < code < test < PRODUCTION
# finding a flaw in design (threat modeling) is far cheaper than an incident in prod
# DevSecOps = "security as everyone's responsibility, automated in the pipeline"
Requirements security and abuse requirements (abuse cases), privacy by design (GDPR)
Design threat modeling (dso-threatmodel), secure architecture decisions
Development secure coding, linters, pre-commit hooks, SAST in the IDE/PR (dso-sast)
Build/CI SAST, SCA (dso-deps), secrets (dso-secrets), IaC scan (dso-iac)
Test DAST, security testing, fuzzing; pentest before release
Deploy hardening, artifact signing, admission policies (dso-cicd, dso-k8ssec)
Operation monitoring, vuln management (def-vulnmgmt), response (dfir)
OWASP SAMM maturity model to assess/improve the AppSec program
BSIMM benchmark of real industry practices
NIST SSDF (800-218) secure development practices
OWASP ASVS application security verification requirements (checklist)
- SAST/SCA/secrets/IaC as CI steps that FAIL the build on critical findings
- balance: gates that don't drown (false positives) nor let the critical through
- results in the PR (fast feedback to the dev) and in a posture dashboard (AppSec)
- managed, expiring exceptions, not "ignore forever"
- Security Champions: one dev per team with a security focus -> scales the program
- secure-coding training; incident retros -> process improvements
- "paved road": secure-by-default templates/libraries that make doing it right easy
  • Automate controls in the pipeline (SAST/SCA/secrets/IaC) with gates proportional to risk.
  • Start with threat modeling in design (Threat modeling in design): the cheapest thing to fix.
  • Measure maturity with SAMM/ASVS and prioritize by risk, not by finding volume.
  • Close the loop with vulnerability management (Vulnerability management) and response (dfir).
  • Equifax (2017): an unmanaged dependency flaw (Struts) in the SDLC → massive breach.
  • SolarWinds (2020): compromising the build/CI (CI/CD security) to inject into the product shifted focus to supply-chain security.
  • Log4Shell (2021): the lack of SBOM/SCA (Dependencies & SCA) determined response capability.
  • Security requirements and abuse cases defined
  • Threat modeling in design (Threat modeling in design)
  • SAST/SCA/secrets/IaC automated in CI with gates
  • DAST/pentest before release
  • Artifact signing and deployment policies (CI/CD security)
  • Monitoring and vuln management in operation (Vulnerability management)
  • Maturity measured (SAMM/ASVS) and Security Champions
  • Managed exceptions with expiry