From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Software assurance

Software assurance

- In this lesson, we're going to talk about software assurance. Now, software assurance is a process to ensure applications meet an acceptable level of security for the functions they're designed to provide. Now, there are many ways to conduct software assurance. These include actions to audit and log the functions performed by the software, the use of standard libraries in the development of the software, industry accepted approaches, web security services and other techniques. The least formal method of software assurance is to use auditing and logging. In this approach, the enterprise environment is continually being audited and logged to, to determine if the applications are acting in a secure and appropriate manner. Any unusual actions are going to be investigated and a root cause is determined. Most enterprise environments utilize risk management across your enterprise. This ongoing process is going to continually look at risks, vulnerabilities, and the appropriate mitigations…

Contents