NIST SP 800-218
E551472
NIST SP 800-218 is a National Institute of Standards and Technology publication that provides secure software development framework guidance for organizations.
Statements (48)
| Predicate | Object |
|---|---|
| instanceOf |
NIST Special Publication
ⓘ
cybersecurity guideline ⓘ secure software development framework ⓘ |
| access | freely available online ⓘ |
| applicableTo |
cloud-based software
ⓘ
commercial off-the-shelf software ⓘ government software acquisition ⓘ on-premises software ⓘ open-source software ⓘ software-as-a-service ⓘ |
| basedOn | NIST Secure Software Development Framework Version 1.1 NERFINISHED ⓘ |
| countryOfOrigin |
United States of America
ⓘ
surface form:
United States
|
| documentType |
best practices framework
ⓘ
technical guidance ⓘ |
| domain |
cybersecurity
ⓘ
secure software development ⓘ software security ⓘ |
| fullTitle | NIST Special Publication 800-218 NERFINISHED ⓘ |
| includesConcept |
governance of software security
ⓘ
protection of software ⓘ response to vulnerabilities in software ⓘ secure software development practices ⓘ |
| language | English ⓘ |
| objective |
improve software security posture of organizations
ⓘ
mitigate the potential impact of exploited vulnerabilities ⓘ reduce the number of vulnerabilities in released software ⓘ |
| primaryFocus |
guidance for secure software development practices
ⓘ
organizational software security processes ⓘ |
| provides |
Secure Software Development Framework
NERFINISHED
ⓘ
tasks and practices for secure software development ⓘ |
| publishedBy | National Institute of Standards and Technology NERFINISHED ⓘ |
| publisher | U.S. Department of Commerce NERFINISHED ⓘ |
| relatedTo |
NIST Cybersecurity Framework
NERFINISHED
ⓘ
NIST SP 800-161 NERFINISHED ⓘ NIST SP 800-53 NERFINISHED ⓘ software supply chain security ⓘ |
| replaces | NIST SSDF Version 1.0 NERFINISHED ⓘ |
| shortTitle |
NIST SSDF
NERFINISHED
ⓘ
NIST Secure Software Development Framework NERFINISHED ⓘ |
| structure |
practices grouped into categories
ⓘ
tasks mapped to practices ⓘ |
| supports |
federal agency cybersecurity requirements
ⓘ
risk management for software development ⓘ |
| targetAudience |
organizations developing software
ⓘ
organizations integrating software ⓘ organizations operating software ⓘ software acquirers ⓘ software producers ⓘ |
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.