Shostack on the NIST SSDF v1.2 Draft

 Adam Shostack wrote that NIST has released a public draft of version 1.2 of NIST 800-218, the Secure Software Development Framework, and invited comments by January 30, 2026. He noted that if that doesn’t matter to you, you can ignore it. He mentioned a news story discussing the draft’s view of application security as a journey and expressed a wish that the document frame its focus on software security issues rather than just software vulnerabilities

https://shostack.org/blog/nist-800-218-revision/

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities