7 ms·
This sounds like Software Security. It's a discipline of information security which covers security and its relation to software and the development that produ
by Jiocus 4y ago
This sounds like Software Security. It's a discipline of information security which covers security and its relation to software and the development that produces it –from minute details such as [1], through abstractions like [2] to architectural [3].
Our infosec tutors regretted that this wasn't mandatory reading for the code-focused computer scientists. Mostly infosec-oriented peers took the subject, who might need it the least.
Security should definitely be promoted with development.
[1]: https://www.cis.upenn.edu/~sga001/classes/cis331f19/resources/low-level-security-by-example.pdf https://www.cis.upenn.edu/~sga001/classes/cis331f19/resource...
[2]: https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ https://owasp.org/Top10/A07_2021-Identification_and_Authenti...
[3]: https://owasp.org/Top10/A04_2021-Insecure_Design/ https://owasp.org/Top10/A04_2021-Insecure_Design/