Security policies in the application development process
ISO 17799 defines a security policy as a document providing management direction and support for information security in accordance with business requirements and relevant laws and regulations. During the software development process it is important to use these policies as a guide for all security features that will be developed.
This point is subtle but critical to understand. The application security policy should not be defined by the development process it should only implement the organizations stated security requirements. Keep in mind that the application you develop needs to fit into the user's security model whether this is your company or your customers.
[ Read more ]