PSIRT
Give this one a try later!
the team that receives, investigates, and reports security vulnerabilities
Final Privacy Review
,Give this one a try later!
done in A5 - final review of compliance against all privacy requirements
identified during the SDL cycle
Fuzz Testing
Give this one a try later!
automated or semi-automated testing that provides invalid, unexpected, or
random data to the computer software program
Waterfall Phases (typical)
Give this one a try later!
plan -> build -> test -> review -> deploy
PRSA1
Give this one a try later!
External Vulnerability Disclosure Response - stakeholders are clearly
identified and a RACI matrix should be created
BSIMM Categories
, Give this one a try later!
governance, intelligence, software security development life cycle
touchpoints, and deployment
PRSA4 & PRSA5
Give this one a try later!
Security Strategy for Legacy Code, M&A, and EOL Plans - strategy to
mitigate security risk from legacy code and M&As
Waterfall Development
Give this one a try later!
software development methodology that breaks down development
activities into linear sequential phases; each phase depends on the
deliverables of the previous one and corresponds to a specialization of
tasks
Alpha Level Testing
Give this one a try later!
testing done by the developers themselves
Give this one a try later!
the team that receives, investigates, and reports security vulnerabilities
Final Privacy Review
,Give this one a try later!
done in A5 - final review of compliance against all privacy requirements
identified during the SDL cycle
Fuzz Testing
Give this one a try later!
automated or semi-automated testing that provides invalid, unexpected, or
random data to the computer software program
Waterfall Phases (typical)
Give this one a try later!
plan -> build -> test -> review -> deploy
PRSA1
Give this one a try later!
External Vulnerability Disclosure Response - stakeholders are clearly
identified and a RACI matrix should be created
BSIMM Categories
, Give this one a try later!
governance, intelligence, software security development life cycle
touchpoints, and deployment
PRSA4 & PRSA5
Give this one a try later!
Security Strategy for Legacy Code, M&A, and EOL Plans - strategy to
mitigate security risk from legacy code and M&As
Waterfall Development
Give this one a try later!
software development methodology that breaks down development
activities into linear sequential phases; each phase depends on the
deliverables of the previous one and corresponds to a specialization of
tasks
Alpha Level Testing
Give this one a try later!
testing done by the developers themselves