Secure Coding
What is Secure Coding?
The practice of writing software code that is resistant to security vulnerabilities. Secure coding practices include input validation, output encoding, proper error handling, and following guidelines such as the OWASP Secure Coding Practices.
Terms that appear alongside secure coding
Each of these is named in at least one of the same controls as secure coding. The number is how many controls name both.
- security testing 11 shared controls
- code review 11 shared controls
- threat modelling 9 shared controls
- vulnerability 9 shared controls
- owasp 8 shared controls
- application security 8 shared controls
- threat modeling 6 shared controls
- nist 4 shared controls
Frameworks that govern secure coding
What the standards actually require on secure coding
Requirements naming secure coding across 6 standards, quoted from the control text.
Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities. Training can include general security principles and application security standard practices.
CIS-16.9 · Train Developers in Application Security Concepts and Secure Coding →Follow secure coding practices for input validation, output encoding, authentication, session management, error handling, and use of secure defaults. Apply practices consistently across languages used in the organization.
SP800-218-PW.5.1 · Secure Coding Practices →Per OWASP DSOMM Implementation dimension: implement secure software development practices. Requirements include (a) maintain secure coding standards aligned to language + framework + with developer guidance + (b) conduct threat modelling at design phase + revi...
DSOMM-2 · Implementation Practices, Secure Coding, and Threat Modelling →Developers must follow defined secure coding practices and use approved development tools, libraries, and frameworks. Code must be reviewed for security defects before integration.
SSLC-6.1 · Secure Coding Practices →Code changes to in-scope systems receive peer review and security scanning before merge to production branches
CO-NewDev-2 · Secure Coding and Code Review →Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...
JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security →Questions people ask about secure coding
What is Secure Coding?
Why is Secure Coding important for compliance?
Which compliance frameworks address Secure Coding?
Where can I learn more about Secure Coding?
See how Secure Coding applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.