New Live Guidelines for Secure Software Development, Security, and Operations Practices

https://www.nist.gov/themes/custom/nist_www/img/homepage/nist_mark.png

The NIST National Cybersecurity Center of Excellence (NCCoE) is releasing a live document as part of its Secure Software Development, Security, and Operations (DevSecOps) Practices project. This project demonstrates how organizations can implement the security practices and tasks recommended in the NIST Secure Software Development Framework (SSDF) using modern DevSecOps pipelines and commercially available technology. The live document is open for public comment until April 24, 2026.

This release provides several components of the NCCoE DevSecOps demonstration, including:

  1. An updated Executive Summary and Introduction, highlighting the purpose and background of this project.
  2. A notional reference model for DevSecOps to demonstrate the NIST SSDF.
  3. Details on the first example implementation, which demonstrates DevSecOps practices in a Microsoft Azure-based environment.
  4. An appendix highlighting industry collaborators in the project and their technologies used in the demonstration environment.

The live document shares findings from the NCCoE's collaborative, demonstrative applied research project with...

Copyright of this story solely belongs to nist.gov. To see the full text click HERE

Read more

https://images.ft.com/v3/image/raw/https%3A%2F%2Fd1e00ek4ebabms.cloudfront.net%2Fproduction%2F0388b243-8957-4ed7-af75-a45c7c09a5f2.jpg?source=next-article&fit=scale-down&quality=highest&wi...

Sources: Revolut told new hires they'll have to work in office at least three days a week from next year, retreating from its long-held remote-first approach

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.