This presentation provided updates on NIST work on the Secure Software Development Framework (SSDF) and Development, Security and Operations (DevSecOps) projects. Including the following:
1. A high level description of what qualities secure software should have that is
2. A common language for discussing and comparing current secure software development practices
3. A way to map this guidance to existing industry guidance for developing secure software
Security and Privacy: cybersecurity supply chain risk management
Technologies: software & firmware