Does performing security code review and vulnerability remediation early in the development life cycle result in any cost savings?
There is agreement among analysts that the earlier in the life cycle that security vulnerabilities are discovered, the cheaper they are to address. Research published by B. Boehm and V. Basali in IEEE Computer found that fixing a software defect after deployment costs more than 100 times what it would have cost to fix it at the first stages of the development life cycle. For security defects, late-stage costs are often much higher, because in addition to having to remediate the flaws, successful exploits may lead to data theft, sabotage, or other attacks.
Related Questions
- Does performing security code review and vulnerability remediation early in the development life cycle result in any cost savings?
- What part did religion play in Maya Angelous early life and in the development of her character ?
- What are the benefits of implementing web application security early in the development cycle?