Secure Development Lifecycle Flashcards

1
Q

Name 2 secure development life cycles

A
  1. Microsoft SDLC
  2. OWASP OpenSAMM (Software Assurance Maturity Model)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name 2 problems that could appear during the design stage of a SDLC

A
  1. Design flaws slip into coding phase
  2. Errors could come from bad requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why dont the test team find security flaws?

A

The test team is looking for mainly functional issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

At the requiements stage how would you mitigate security issues? (2)

A
  1. Education
  2. Risk analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

At the design stage how would you mitigate security issues?

A
  • Threat Modelling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

At the code stage how would you mitigate security issues?

A
  • Secure code reviews
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

At the test stage how would you mitigate security issues?

A
  1. Risk analysis
  2. pen testing (final stage is bad practise)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly