Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

How is the CWE initiative related to the DHS’ Software Assurance efforts?

0
Posted

How is the CWE initiative related to the DHS’ Software Assurance efforts?

0

CWE has matured through collaborative efforts of the Software Assurance Forum and SwA working groups https://buildsecurityin.us-cert.gov/swa/. CWE provides the requisite characterization of exploitable software constructs; thus it better enables the needed education and training of programmers on how to become aware and informed about these types of errors before software is delivered and put into operation. This aligns with the DHS “Build Security In” approach to software assurance so that software is developed more securely on the front end, thereby avoiding security issues in the longer term. It provides a standard means for understanding residual risks; thus enables more informed decision-making by suppliers and consumers about the security of software. CWE also enables the interoperable automation of Software Assurance EcoSystem components and projects, such as the NIST Software Assurance Metrics and Tool Evaluation (SAMATE) project that is sponsored by DHS NCSD Software Assurance

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123