Security requirements
Security requirements depend on the business environment, regulations, and security compliance. An organization should define a minimum expected security requirement baseline to be part of the release gate. Based on the severity and impact, the release plan may be a release conditional on the readiness of hotfixes, not released until the issue is fixed, released with mitigation protection, and so on.
To have a security requirement release baseline will also help to build consensus among stakeholders such as IT, development teams, security teams, and so on. Otherwise, it may be that business teams would like to release even though there are security defects, while the security team may not endorse the release.
It's a ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access