Deploying security tools and writing secure coding policies does not prove software is secure. Organizations need ways to assess whether their software security efforts are actually working, both for individual applications and for the development program as a whole. Three tools for this are auditing, logging and risk analysis, tied together by metrics that show trends over time and feed improvements back into the process.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.