..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Software Development Life Cycle Security

commissum consulting services include audits, security healthchecks, ISO27001 reviews, CLAS consultancy and policy creation and management.

Our security awareness, training and education services allow organisations to enhance their employees' awareness and understanding of information security issues through managed awareness programmes, and delivery of training and educational products.

Application Security

Issues

Despite widespread awareness of the risks as compared with only five years ago, it is unfortunate that applications are still frequently the weak points in system security. This is backed up by the findings of an independently commissioned study conducted by Forrester Consulting. The study interviewing a number of development, security and risk professionals across both the US & UK, found that while companies feel they understand the business criticality of their various application portfolios, they actually have little confidence in the quality of the security of the applications.

  • Only 13% of respondents are confident in the security quality of applications which are critical to the business.
  • Only 34% of organisations surveyed had comprehensive SDLC processes incorporating security considerations.
  • at least 57% of organisations surveyed did not have effective training programmes addressing security training for developers.

In today's environment, time-to-market is critical for application development. There is always a delicate balance between functional requirements, business needs, and security risk. Organisations are understandably focused on ensuring that business functional requirements are delivered by developers. In this environment, it is too easy to overlook critical flaws in design or underlying vulnerabilities in the commercial-off-the-shelf components that are inevitably part of the application, or part of the environment in which it operates.

Approach

Ideally, a client will engage the services of commissum’s assurance specialists at the earliest phases of a project; it is significantly more cost effective to design with best practice security in mind from the start. However, the knowledge and skills of the commissum team can be applied at any or all stages.

Our standard approach ensures that four key aspects are involved in the SDLC:

  • Governance: the essential processes related to how an organisation manages its software development lifecycle
  • Development: processes related to how an organisation defines the objectives and requirements for the software, and designs and develops software within projects
  • Verification: processes related to an organisation testing elements created throughout development, both prior to and following release
  • Deployment: processes related to an organisation managing the release of software it creates to a production environment
  • Support - processes related to an organisation managing the through-life support of software through development process change control, patch management, and training

commissum is able to apply its service portfolio to support the assurance requirements of projects, from large scale turnkey enterprise projects to discrete, single focus development projects; experience here has come from both private and public sectors and can be applied throughout the project lifecycle. Examples include:

  • Management Frameworks – assisting in implementing project management frameworks to ensure assurance/security considerations are firmly embedded in the lifecycle. This ensures that Security is involved as early as possible; ideally from the Requirements phase, and through design, to implementation, test, production and through-life support; ensuring appropriate controls are part of and integral to the evolving solution.
  • Gap Analysis – essentially a tightly scoped audit against best practice as applied to the processes adopted for managing the security controls for projects. These can either be those applied to the conduct of the overall project, or ensuring that security considerations are appropriately built into the development of project deliverables.
  • Project Assurance Support – throughout the lifecycle, appropriate input to the management, design, development and test/acceptance processes. This can include analysis and input to requirements definition, design review at various stages, workshop facilitation, project team training, and test plan development. The key here is that is more efficient establishing security principles and identifying issue early, than taking later corrective action.
  • Security Testing – an area of core competency is our security testing capability, validating the effectiveness of designed and implemented Security controls. This would typically address infrastructure and application layers, albeit often at different sages of development. Testing also confirms that controls provide the right balance between system security and operational effectiveness. As a minimum this usually involves testing of production systems prior to and immediately following go-live. In a SDLC context testing should be planned into the schedule from the early stages.
  • Training – according to the report issued by Forrester, 57% of organizations do not have effective training programs addressing security training for their developers. commissum can provide training from basic awareness of secure development issues to specific technology security training.
  • Through-Life Support – ongoing support of systems through monitoring and update. Application of appropriate management frameworks for change control. commissum will provide advice or a full turnkey service as required.

Benefits

Involving commissum and security considerations early in the SDLC results in a overall more efficient development process, significantly reduced time and cost overruns owing to late project redesigns, a secure system and satisfied business stakeholders.

It is worth noting the documented and measured experience of Microsoft in this regard. Microsoft’s Trustworthy Computing SDL was introduced as a new life cycle approach that sought to embrace the critical elements of security to be embedded within the development life cycle; this was to ensure that security was appropriately considered as part of normal development. As a result of this initiative, it is documented that Microsoft reported 60% fewer vulnerabilities in its operating systems released in 2008 than in 2002.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
“We have used commissum for several years and their work has always been professional and delivered to a high standard. We appreciate their ability to readily interpret project requirements and to make a valuable contribution even when a project's budget is tight. commissum are easy to deal with and have the flexibility to manage changing time scales and requirements.”

Mr Iain R, Account Director, International Business Systems & Managed Services Company

Latest News

Alleged Chinese Government Hacking Department back in action

Alleged Chinese Government Hacking Department back in action

Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...
Tue 21 May, 2013 // Martin
cyber-war

Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years

A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...
Wed 08 May, 2013 // Briony
cyber-tanks

Suspected hacker arrested after “biggest-ever DDoS attack”

Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...
Tue 30 Apr, 2013 // Briony