Secure Development Lifecycle

Also known as:SDL · SSDLC

Secure Development Lifecycle: Integrates security activities into all phases of software development. The term relates to the security of applications, interfacesInterfaceA defined boundary through which systems, components, or users exchange data and commands., or development processesDevelopment ProcessThe organized workflow used to design, implement, test, release, and maintain software.. Relevant measures range from secure designSecure DesignDesigning systems so security requirements and trust boundaries are addressed before implementation. and testing to runtime protection and rapid remediationRemediationThe correction or mitigation of a confirmed security weakness, defect, or misconfiguration..

How it works and where it fits

Secure Development Lifecycle places security within the lifecycle of software and technical change. Requirements, architecture, implementation, testing, release, and maintenance affect one another. The earlier a weakness or unsafe assumption is identified, the more precisely it can be corrected without relying solely on downstream security products.

Practical security relevance

Practical implementation requires explicit quality criteria, reviewable changes, and a traceable supply chain. Automated checks provide rapid feedback but do not replace threat modeling or manual analysis of security-critical logic. Dependencies, build systems, artifacts, and secrets need protection alongside source code; operational and incident findings feed back into development.

  • DevSecOpsDevSecOpsIntegration of security practices into development, deployment, and operations.: Integration of security practices into development, deployment, and operations.
  • Secure CodingSecure CodingProgramming practices aimed at avoiding common vulnerabilities and misconfigurations.: Programming practices aimed at avoiding common vulnerabilities and misconfigurations.
  • Application SecurityApplication SecurityProtects software against vulnerabilities during development, operation, and maintenance.: Protects software against vulnerabilities during development, operation, and maintenance.
  • Source Code AnalysisSource Code AnalysisExamination of source code for vulnerabilities, errors, and insecure patterns.: Examination of source code for vulnerabilities, errors, and insecure patterns.