In most safety critical sectors, the practices surrounding the development of functionally safe application software are well established and familiar. Standards such as DO-178C in aerospace, ISO 26262 in automotive and IEC 61508 in industry are now long established, as is the industry that supports them.
Connectivity brings with it new questions, new terminology, and a changed emphasis of a system defended from the world, rather than a world defended from a system. Small wonder that the development of appropriate standards lags behind the demand for their existence, but are relatively vague when they do become available!
This presentation will look beyond that vagueness to suggest that the application of “defence in depth” combining secure architectures, least privilege principles, domain separation technologies, and secure coding and test techniques, will make a system as secure as technology will allow. In showing that secure application code has a significant part to play in that defence strategy, it will explore the concepts of the “Shift left paradigm”, “SAST” and “DAST”. And it will discuss the techniques that can be applied such that their introduction compromises neither the integrity nor the productivity associated with an established, functionally safe, application development lifecycle.
In most safety critical sectors, the practices surrounding the development of functionally safe application software are well established and familiar. Standards such as DO-178C in aerospace, ISO 26262 in automotive and IEC 61508 in industry are now long established, as is the industry that supports them.
Connectivity brings with it new questions, new terminology, and a changed emphasis of a system defended from the world, rather than a world defended from a system. Small wonder that the development of appropriate standards lags behind the demand for their existence, but are relatively vague when they do become available!
This presentation will look beyond that vagueness to suggest that the application of “defence in depth” combining secure architectures, least privilege principles, domain separation technologies, and secure coding and test techniques, will make a system as secure as technology will allow. In showing that secure application code has a significant part to play in that defence strategy, it will explore the concepts of the “Shift left paradigm”, “SAST” and “DAST”. And it will discuss the techniques that can be applied such that their introduction compromises neither the integrity nor the productivity associated with an established, functionally safe, application development lifecycle.
Email: info@ldra.com
EMEA: +44 (0)151 649 9300
USA: +1 (855) 855 5372
INDIA: +91 80 4080 8707