DarkEngine: CyberCX Uncovers Highly Orchestrated WordPress Phishing Campaign →

Driving the development of more secure software

Cyber Security Strategy

Published by Security Testing and Assurance on 22 June 2023

 

One of the key outcomes of the recent Quad Leaders’ Summit, held in Hiroshima, Japan, was the establishment of a set of secure software development principles. With these principles, the four Quad nations — Australia, India, Japan, and the United States — have “re-affirmed their commitment to improve software security” (Quad Senior Cyber Group, 2023), and to build policy frameworks to guide the development, procurement, and use of software.  

In agreeing to these joint principles, Quad governments stated their collective intent to use their formidable purchasing power to “drive the development of safer and more secure software.” 

Although the principles are targeted towards government vendors and governments themselves, they can be applied to any organisation developing or procuring software.  

 

What guidelines already exist? 

Guidelines for developing secure software are not a new concept. Most well-established cyber security frameworks, such as ISO 27001 and the NIST Cybersecurity Framework, contain sections focused on software development. As software security has come under greater scrutiny, more specific and detailed industry standards have emerged.  

The Australian Information Security Manual (ISM) contains also ‘Guidelines for Software Development’ and these are most likely going to be the starting point for any additional policy or regulatory guidance. Given the focus, there is a possibility of seeing these controls included in an expanded version of the Essential 8 in the future.

 

What can organisations do now? 

CyberCX provides full end-to-end services to support organisations in building and maintaining secure software solutions. To learn more, reach out to [email protected]

 

References 

 

Author: Raafey Khan – Managing Consultant Application Security

 


 

We are hiring! CyberCX currently have open offensive roles in penetration testing, adversary simulation, and AppSec for Australia and New Zealand. If you are interested in working with the largest and most capable team in the region in a fun, rewarding, and challenging environment, please send your CV to [email protected]

Other Cyber Security Resources

Ready to get started?

Find out how CyberCX can help your organisation manage risk, respond to incidents and build cyber resilience.