A Security Practices Evaluation Framework

Pre-Release Vulnerabilities


Description

Vulnerabilities discovered during the development process should be credited to the team and its development practices.

Definition

Vulnerabilities found in new and changed code before software is released.

Data Collection

When a vulnerability is found in new or changed code before the software is released, Collect the Per-Vulnerability attributes and mark the development phase where the software was found; Requirements, Design, Development, Testing. Count total number of vulnerabilities found in new and changed code before the software is released.