Software security’s pillars
what makes a good software risk assessment is the ability to apply classic risk definitions to software design in order to generate…
Wiki topics:
CRY · Crypto & Web3
Software security’s pillars

what makes a good software risk assessment is the ability to apply classic risk definitions to software design in order to generate accurate mitigation requirements.


applied risk management
process of identifying, analyzing, and prioritizing security risks based on business impact.
key points:
- identify threats and vulnerabilities
- assess risk = likelihood x impact
- prioritize critical assets
- plan mitigation strategies
- continuous monitoring
software secturity touchpoints
security activities integrated throughout the SDLC.
major touchpoints:
- security requirements
- architecture risk analysis
- threat modeling
- code review
- static analysis
- penetration testing
- security testing
knowledge
security expertise and shared information used to prevent vulnerabilities.
includes:
- OWASP TOP 10
- secure coding standards
- attack patterns
- security design patterns
- developer training
asking good questions: what to protect? how to protect it? what do we know about it?
메타데이터
- post_id
- bfabba70f19e
- slug
- software-securitys-pillars-bfabba70f19e
- url
- https://medium.com/@CyberGee/software-securitys-pillars-bfabba70f19e
- canonical_url
- https://medium.com/@CyberGee/software-securitys-pillars-bfabba70f19e
- author_url
- https://medium.com/@CyberGee
- status
- ok
- fetched_at
- 2026-06-16 19:09:56