• Skip to primary navigation
  • Skip to content
  • Skip to footer
TSS-WEB TSS-WEB
  • Secodis GmbH
    • General
      • 1. Types of Requirements
      • 2. Terms
      • 3. Roles
      • 4. Risk Classes
      • 5. FAQ
      • 6. License
    • SSDLC Requirements
      • A.1 - Secure Dev Environment
      • A.2 - Secure Development Process
      • A.3 - Security Tests
      • A.4 - Outsourced Development
      • A.5 - Secure Operation
    • Implementation Requirements
      • B.1 - Secure Design Principles
      • B.2 - Input Validation
      • B.3 - Secure Fileuploads and Downloads
      • B.4 - Output Validation
      • B.5 - Secure User Registration & Authentication
      • B.6 - User Passwords
      • B.7 - Secure Session Management
      • B.8 - Authorization
      • B.9 - Error Handling and Logging
      • B.10 - Data Security
      • B.11 - Protection of Secrets
      • B.12 - API Security
      • B.13 - Client-Side Security
      • B.14 - HTTP Header Security

    Microsoft SDL Mapping

    Microsofts new SDL is fully covered by TSS-WEB.

    SDL Practice TSS-WEB Coverage
    Establish security standards, metrics, and governance Actually what TSS-WEB is about.
    Require use of proven security features, languages, and frameworks Covered in A.2.3 Secure Design.
    Perform security design review and threat modeling Covered in A.2 - Secure Development Process.
    Define and use cryptography standards Covered in B.10 - Data Security.
    Secure the software supply chain Covered in A.2 - Secure Development Process as well as in A.4 - Outsourced Development.
    Secure the engineering environment Covered in A.1 - Secure Dev Environment
    Perform security testing Covered in A.3 - Security Tests.
    Ensure operational platform security Covered in A.5 - Secure Operation.
    Implement security monitoring and response Covered in A.5.8 Security Monitoring and Alerting and A.5.11 Incident Management.
    Provide security training Covered in Roles.
    • GitHub
    © 2024 TSS-WEB. Powered by Jekyll & Minimal Mistakes.