Why do so many organizations still struggle to implement "secure by design" in software development?
Secure software development?
Goodbye SDLC, Hello SSDF! What is the Secure Software Development Framework?
I'm sure someone, somewhere is building a certification around this right now to charge for
More on reddit.comWhich Framework is best for Software Development
Videos
Hi everyone,
I just started a small dev company with two tech partners. They handle the coding, I focus on the business side, trying to learn all I can about the big problems companies have with making secure software.
Here's what I'm thinking about:
Why isn’t “secure by design” the norm yet?
What stops companies from making secure things right from the start? Is it the cost? Time? Not knowing enough? Or maybe too many parts?
I'd love to know what you've seen, whether you're a dev, CTO, consultant, security pro, or anything else.
I'm not here to sell, just eager to learn and curious. Thanks for any ideas.