Security/Reviews/Secure Development Lifecycle: Difference between revisions

 
(3 intermediate revisions by the same user not shown)
Line 1: Line 1:
= Document Status =
* DRAFT
* Will soon be open for comment with Mozilla Security Community on security-group and dev-security-policy
= Objective =
= Objective =


* Quickly bring products and applications to market with integrated and verified controls that mitigate security and privacy risks to an understood and acceptable level  
* Quickly bring products, applications, and features to market with integrated and verified controls that mitigate security and privacy risks to an understood and acceptable level  
* Capture the overall review lifecycle that ensures Mozilla applications, services and supporting infrastructure are appropriately supported in the areas of :
* Capture the overall review lifecycle that ensures Mozilla applications, services and supporting infrastructure are appropriately supported in the areas of :
** Security
** Security
** Privacy  
** Privacy


= Mozilla Development Lifecycle Overview=
= Mozilla Development Lifecycle Overview=
The mozilla development lifecycle is fluid and informal. In the early stages projects often flow between Prototype and Design & Development stages frequently.
The mozilla development lifecycle is fluid and informal. In the early stages projects often flow between Prototype and Design & Development stages frequently.
[[image:SecureDevelopmentLifecycle.png|600px|Image: 600 pixels]]


== Phases of Development Lifecycle ==
== Phases of Development Lifecycle ==
Line 23: Line 22:
** Web Applications - Production Server
** Web Applications - Production Server


= Mozilla Secure Development =
= Mozilla Secure Development =
Note: This process is flexible and adjusts to meet the demands of the particular project. Our goal is to responsibly get code to market and work together to identify any risks that we should be aware of.
Note: This process is flexible and adjusts to meet the demands of the particular project. Our goal is to responsibly get code to market and work together to identify any risks that we should be aware of.
Confirmed users
491

edits