Secure Development Policy
Secure Development Policy
Secure Development Policy
DEVELOPMENT
POLICY
1
© Distributed by Resilify.io under a Creative Commons Share Alike License.
Secure Development Policy
Version Control
Owner Version Edited By Date Change History
IS Rep 0.1 Assent 14/07/2006 First Draft
Distribution
Held Format Location Comments
By
User Digital / Physical
Status
X Status Approved By Date
Working DD/MM/YYYY
X Draft
Provisional Approval
Publication
Classification
Please refer to ISMS 02 Information Handling & Classification Procedure
X Confidential
Restricted
Unclassified
Relevance to Standard
License
2
© Distributed by Resilify.io under a Creative Commons Share Alike License.
Contents
3
© Distributed by Resilify.io under a Creative Commons Share Alike License.
Secure Development Policy
1.0 Overview
This policy sets out the organization’s approach to developing systems in-house
and/or with the assistance of outsourced development.
2.0 Policy
2.1.1 Methodology
2.1.3 Sprints
2.1.4 Releases
4
© Distributed by Resilify.io under a Creative Commons Share Alike License.
2.2 Environments
2.2.1 Table
Name Description
Development Source code distributed by GIT.
Testing / Separate testing environment using virtual
Staging servers.
Host naming convention: test.xxxx.xxx
Production Live environment.
2.3.2 Design
5
© Distributed by Resilify.io under a Creative Commons Share Alike License.
2.3.4 Testing (Test Environment)
Every major release of the code will be Pen Tested with particular
emphasis on the OWASP Top 10.
6
© Distributed by Resilify.io under a Creative Commons Share Alike License.
2.7 Escrow
Password Policy.
Access Control Policy
Patching Policy
7
© Distributed by Resilify.io under a Creative Commons Share Alike License.