What secure development evidence should a software buyer request?

Discussion

Open questionLast verified: 2026-08-13
  • Author
    Posts
  • #3451

    Security questionnaires often focus on production controls and say little about how the software is built. What evidence is actually useful?

    #3452
    Accepted answer

    Ask how the vendor protects source code and build systems, reviews changes, manages dependencies, tests security, handles vulnerabilities, separates environments, signs releases, and remediates defects. Match the depth of evidence to product risk and avoid demanding sensitive artifacts that the buyer cannot protect or assess. Contract for material remediation and change notice. NIST SP 800-218 provides a common secure software development framework.

    #3522
    Community reply

    What should a small buyer do if it receives secure development documents but has no specialist to assess them?

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account