How can I make sure that my outsourced software undergoes a code review prior to deployment?
Organizations can ensure security of their outsourced applications by requiring a security audit of the source code as part of the outsourcing contract. Ounce Labs has published sample contract language for software development that sets specific security standards and ensures that outsourced code is developed with security from the ground up, and is validated prior to acceptance.
Related Questions
- Must I have my encryption commodities and software approved as a "retail" product prior to submitting them for review as a "mass market" product?
- How can I make sure that my outsourced software undergoes a code review prior to deployment?
- Does publishing exploit code prior to a patch help software security?