Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 2nd September 2026 at 9:02 am #3451
Security questionnaires often focus on production controls and say little about how the software is built. What evidence is actually useful?
2nd September 2026 at 1:00 pm #3452Accepted answerAsk how the vendor protects source code and build systems, reviews changes, manages dependencies, tests security, handles vulnerabilities, separates environments, signs releases, and remediates defects. Match the depth of evidence to product risk and avoid demanding sensitive artifacts that the buyer cannot protect or assess. Contract for material remediation and change notice. NIST SP 800-218 provides a common secure software development framework.
3rd September 2026 at 1:11 am #3522Community replyWhat should a small buyer do if it receives secure development documents but has no specialist to assess them?
- AuthorPosts
- You must be logged in to reply to this topic.