GovReady / security-stories-nist800-53

A collection of security related user stories compatible with NIST Special Publication 800-53
GNU General Public License v2.0
33 stars 15 forks source link

Evaluate Safe Code user stories #18

Open jlyon opened 7 years ago

jlyon commented 7 years ago

http://safecode.org/publications/#safecodepublications-192

Spend ~1hr looking at these stories against the stories we've written and add some observations of them vs ours. Whether they suggest anything about the stories we've written. Add to #11

aschmoe commented 7 years ago

Thoughts:

jlyon commented 7 years ago

Other Sources

While SAFECode’s Fundamental Practices for Secure Software Development already lists a set of engi- neering tasks for creating more secure software, it may not be readily apparent to Agile development teams how best to incorporate these tasks into their unique environments. This section breaks down the Fundamental Practices into familiar Agile “stories” focused on security and derived from the issues most commonly seen by SAFECode members in their environments. Both the CWE/SANS Top 25 Most Dangerous Development Errors list (plus the 16 weaknesses on the cusp list) and the OWASP Top 10 list were also consulted to ensure broad coverage.