In this episode of What That Means, Vernetta Dorsey, a Product Security Staff Engineer at Intel, and Diana Carroll, a Product Security Expert, get to the heart of the secure development lifecycle (SDL) with Camille. Whether this is a brand new topic to you or you’re looking to scale up your existing SDL, they give fantastic insight across the board.

We cover:

  • What the secure development lifecycle is and why it is so essential to get right from the beginning

  • Why forward-thinking, integrated partnerships are meaningful when it comes to SDL

  • How someone might effectively go about scaling up a secure development lifecycle across an organization

  • Additional support systems and processes to consider for your secure development lifecycle

  • The similarities and differences between SDL as it applies to hardware and software

...and more. Check it out!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • A security development lifecycle (SDL) is what companies in the industry utilize to make better products.

  • SDL is most effective when security attributes are incorporated from the get-go. However, even after your product has been released, you still need to focus on maintaining it due to the ever-changing nature of the industry landscape and emerging threats.

  • It’s crucial to know how long you want to support your product so that you can adapt as needed.

  • Companies should always be thinking about worst-case scenarios to prevent them from happening.

  • It’s important to form an integrated partnership between those developing the products and a security or product assurance organization so that no detail goes overlooked.

  • Automation can be a great labor-saver, but that doesn’t mean AI can do everything for you, and you have to be sure you’re putting in the proper maintenance.

  • Scaling up a secure development lifecycle should be a gradual and collaborative process because rushing it, especially if people aren’t aligned, tends to go poorly.

Some interesting quotes from today’s episode:

When we talk about the security development lifecycle, we're talking about certain attributes, assessment tasks or activities that one would want to include in their product development lifecycle.”

“One of the things that we've learned over the years is that it's much easier and more cost-effective if you start incorporating your security attributes in at the beginning, rather than trying to tack them on later, after the fact.”

“We find the most issues when people don't think about the ultimate, the bad case. And that's why it's critically important that this fits within the actual development and engineering teams.”

“Nobody knows a product better than the people that are building it. And that can be their biggest strength. And sometimes a weakness too, because the thing about not seeing the forest for the trees kind of comes into effect. Sometimes somebody is so focused down in the details, that they need somebody to help them zoom out and look at that bigger picture, that broader forest, of how it needs to interact with all these other parts of the ecosystem.”

“Automation can be very valuable. Because from a developer's perspective, or a validator’s perspective, I would often find myself in the spot where if I had to do something more than two or three times, I would rather write a script to do it for me and focus on something else.”

“One of the things I have seen is when somebody builds out this great automation system, and then they don't maintain it for a few years, it can go from becoming a great helper to a handicap.”

“If you don't have that expertise in-house, today, there are places you can go to help build that out.”

“If you try to go from zero to 100 miles per hour all at once, it's going to be a shock to the system. And that's often tended not to go so well. I would say pick a place to start and focus on incrementally adding and improving and expanding the scope of what you're doing.”

“You have to really know your company culture, know your development engineers, to understand which lever you would need to engage and to get everyone on board to where you want to go.”

“If you don't have the validation systems, and the ability to update products after you've shipped them out, or things like that, that impacts not only your overall quality, but also your ability to respond and improve your security and products as well.”

“It's really important to get your architecture right because once you burn something in, you can't fix it, versus the software where you have the capability to make updates and changes much later in the process.”

“Regardless of whether you're talking hardware or software, or even different types of software, context is key.”

“If we're not thinking about it, that means the hackers or the bad actors have more opportunities to take this thing that someone's making for the good of humanity and use it in a way that was not intended.”