SA-8 Security and Privacy Engineering Principles
Description
It is crucial for the university to follow a common set of principles for software development that prioritize security and privacy. By doing so, we can ensure that security is a top priority throughout the development process, from initial design to final deployment.
Applicability
- The information resource owner, or designee, is responsible for ensuring that the measures described in this Control are implemented.
Implementation
-
1Information resource owners shall apply the following security and privacy engineering principles in the specification, design, development, implementation, and modification of university information resources:
-
1.1Prioritize automation and integration.
-
1.2Developer autonomy
-
1.3Continuous improvement
-
1.4Shared responsibility
- 1.4.1Security is everyone’s job. Developers, operations, and security personnel should be empowered to manage security risks together in each phase of the lifecycle.
- 1.4.2Sharing responsibility means that communication needs to be fast, smooth, and effective to ensure timely identification and resolution of security risks.
-
1.5Learning as part of the job
-