Draft:NIST Secure Software Development Framework: Difference between revisions
-- Draft creation using the WP:Article wizard -- |
(No difference)
|
Revision as of 14:18, 2 December 2024
Draft article not currently submitted for review.
This is a draft Articles for creation (AfC) submission. It is not currently pending review. While there are no deadlines, abandoned drafts may be deleted after six months. To edit the draft click on the "Edit" tab at the top of the window. To be accepted, a draft should:
It is strongly discouraged to write about yourself, your business or employer. If you do so, you must declare it. Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Last edited by 65.246.13.11 (talk | contribs) 10 days ago. (Update) |
SSDF was developed by NIST based on US Presidential Executive Order 14028 Section 4 (dated May 12, 2021). It provides a framework for securely developing software in the wake of software supply chain attacks and the prevalent use of open source software and third-party libraries. A major concept that was made popular by SSDF was the software bill of materials (SBOM) and the need for documenting the provenance (origin and history) of all software used in a system.
The first version of SSDF (NIST SP 800-218) was published in Feb 2022.
In general, any software that ends up being in a system sold to a federal agency, must have an SSDF self-attestation form submitted by the developer.