CSIS 343 – Cyber security
Week 4
30th October
Assignment 4: Secure Software Development Practices for Software Development
Company
Due Week 4 and worth 75 points
Instructions: You are tasked with developing guidelines for secure software development
practices for a software development company that creates applications for various clients. Write
a six to eight-page paper addressing the following questions:
1. Provide an overview of secure coding principles and their importance in preventing common
software vulnerabilities. Discuss how adherence to secure coding practices can contribute to the
development of more secure software.
2. Evaluate the effectiveness of code review and static analysis in identifying and mitigating security
vulnerabilities. Discuss how these practices can be integrated into the software development
lifecycle to ensure the early detection of security issues.
3. Propose guidelines for implementing secure authentication and authorization mechanisms in
software applications. Discuss the importance of protecting user credentials and ensuring proper
access controls.
4. Discuss strategies for implementing data encryption in software applications to protect sensitive
information. Address considerations for user privacy and compliance with data protection
regulations.
5. Recommend secure DevOps practices to integrate security into the software development
process. Discuss the role of automation, continuous integration, and continuous delivery in
maintaining a secure development environment.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all
sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Compare and contrast the methods of disaster recovery and business continuity.
Explain risk management in the context of information security.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing mechanics and
technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 75 Assignment 4: Secure Software Development Practices for Software Development
Company
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain the basic
primary tasks, ongoing
evaluations, and major
policy and procedural
changes that would be
needed to perform as
the BC lead / manager.
Weight: 20%
Did not submit or
incompletely
explained the
basic primary
tasks, ongoing
evaluations, and
major policy and
procedural
changes that
would be needed
to perform as the
BC lead /
manager.
Insufficiently
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Partially
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Satisfactorily
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Thoroughly
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
2. Provide insight on
how to plan the
presentation to garner