Commenting on this, Ray Kelly, fellow at Synopsys Software Integrity Group, shared:

“CISA is making great progress with providing guidance to help keep organisations safe from cyberattacks. Building security into the design process is not only good practice, it’s also very effective in mitigating flaws in software before they reach the consumer. The challenge, however, is for organisations to adopt these practices without affecting the business, as this process takes time and requires resources that can impact the bottom line. The ‘design stage’ is a critical component of the software development lifecycle (SDLC) and organisations continue to struggle adopting security as part of this process. Hopefully, CISA’s latest recommendations will help bring more visibility on importance of building security into the SDLC from the start.”