Secure SDLC
A Secure SDLC integrates security across the whole development lifecycle, instead of leaving it as an audit at the end. The principle is shift-left: the earlier a flaw is found, the cheaper it is to fix — a design bug in production costs orders of magnitude more than in the requirements phase.
Why shift-left
Section titled “Why shift-left”Cost to fix a flaw: requirements < design < code < test < PRODUCTION# finding a flaw in design (threat modeling) is far cheaper than an incident in prod# DevSecOps = "security as everyone's responsibility, automated in the pipeline"Security by phase
Section titled “Security by phase”Requirements security and abuse requirements (abuse cases), privacy by design (GDPR)Design threat modeling (dso-threatmodel), secure architecture decisionsDevelopment secure coding, linters, pre-commit hooks, SAST in the IDE/PR (dso-sast)Build/CI SAST, SCA (dso-deps), secrets (dso-secrets), IaC scan (dso-iac)Test DAST, security testing, fuzzing; pentest before releaseDeploy hardening, artifact signing, admission policies (dso-cicd, dso-k8ssec)Operation monitoring, vuln management (def-vulnmgmt), response (dfir)Reference frameworks
Section titled “Reference frameworks”OWASP SAMM maturity model to assess/improve the AppSec programBSIMM benchmark of real industry practicesNIST SSDF (800-218) secure development practicesOWASP ASVS application security verification requirements (checklist)Pipeline automation (gates)
Section titled “Pipeline automation (gates)”- SAST/SCA/secrets/IaC as CI steps that FAIL the build on critical findings- balance: gates that don't drown (false positives) nor let the critical through- results in the PR (fast feedback to the dev) and in a posture dashboard (AppSec)- managed, expiring exceptions, not "ignore forever"Culture and champions
Section titled “Culture and champions”- Security Champions: one dev per team with a security focus -> scales the program- secure-coding training; incident retros -> process improvements- "paved road": secure-by-default templates/libraries that make doing it right easyBlue Team / AppSec
Section titled “Blue Team / AppSec”- Automate controls in the pipeline (SAST/SCA/secrets/IaC) with gates proportional to risk.
- Start with threat modeling in design (Threat modeling in design): the cheapest thing to fix.
- Measure maturity with SAMM/ASVS and prioritize by risk, not by finding volume.
- Close the loop with vulnerability management (Vulnerability management) and response (dfir).
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Equifax (2017): an unmanaged dependency flaw (Struts) in the SDLC → massive breach.
- SolarWinds (2020): compromising the build/CI (CI/CD security) to inject into the product shifted focus to supply-chain security.
- Log4Shell (2021): the lack of SBOM/SCA (Dependencies & SCA) determined response capability.
Testing checklist
Section titled “Testing checklist”- Security requirements and abuse cases defined
- Threat modeling in design (Threat modeling in design)
- SAST/SCA/secrets/IaC automated in CI with gates
- DAST/pentest before release
- Artifact signing and deployment policies (CI/CD security)
- Monitoring and vuln management in operation (Vulnerability management)
- Maturity measured (SAMM/ASVS) and Security Champions
- Managed exceptions with expiry