Summary
We discussed security requirements in four areas. We provided samples of how to define security release gates for each development stage, such as design, coding, build, testing, delivery, and monitoring. CVSS evaluation is also suggested whenever there is a dilemma: whether to go for the next release or not.
For a product manager to plan security features, we recommend OWASP ASVS. Depending on the business scenario, there are three levels of security. Based on the OWASP ASVS, an open source OWASP Security Knowledge Framework was introduced to help an organization to set up an in-house security knowledge portal.
For data security and privacy, we discussed the security requirements for big data.
For big data requirements, the CSA defines ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access