3 ms·
We license people to drive and have a legal system for dealing with irresponsible drivers.
by staticassertion 4y ago
We license people to drive and have a legal system for dealing with irresponsible drivers.
- BaculumMeumEst 4y agoCompanies have policies for software security. Industries have regulations.
- staticassertion 4y agoThe most common policy will be for SOC2, ISO27001. There's virtually nothing about software security in there, other than scanning for vulnerabilities. Everything else is about controls on infrastructure, threat modeling, that sort of thing. It's not really relevant. Besides, none of those have to do with software engineers. Compliance doesn't imply any individual responsibility.
- BaculumMeumEst 4y agoThe most common policy for what? I've worked in defense and there are stringent security requirements for applications and servers, which programs written in manual memory management languages would likely fail. "Some existing policies are bad" is not a convincing argument that hare shouldn't exist.
- staticassertion 4y agoThe most common for companies to have/ be required to have. > I've worked in defense and there are stringent security requirements for applications and servers. Like? FEDRAMP? The vast majority of compliance is about threat modeling and access controls.
- BaculumMeumEst 4y ago> Like? FEDRAMP? No, STIGs. > The vast majority of compliance is about threat modeling and access controls. If compliance doesn't address security, that sounds like a bigger issue than a new hobby language existing.
- staticassertion 4y agoThe issue is that no one is taking responsibility for writing safe software. Compliance / regulation isn't, developers aren't either.