Secure coding standards give developers concrete rules for writing software that resists attack. They turn broad principles into practices that can be taught, checked by tools and enforced in code review. Well-known references include the OWASP Top 10 (the most critical web application security risks), the OWASP Application Security Verification Standard (ASVS), the Common Weakness Enumeration (CWE) list of software weakness types and its Top 25 most dangerous weaknesses, the SEI CERT coding standards for specific languages, and the NIST Secure Software Development Framework (SSDF). Organizations usually adopt one or more and tailor them to their languages and platforms.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.