<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SDLC definition in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26011#M5206</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is so low level and really context-related but I have been referencing both the SDLC as we been taught as meaning the "Software development lifecycle" but also been referencing ISO 27034 where the definition for SDLC is "Systems Development Life Cycle(s)".&amp;nbsp; This was raised in peer review in a document as slightly unclear.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are somewhat interchangeable conceptually perhaps but should ISC2 perhaps adopt the ISO definition instead or tweak it to make it not clash?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just added the acronym twice in my definitions table and expanded on first use in the paragraph to allow context.&lt;BR /&gt;&lt;BR /&gt;Wayne&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jul 2019 10:10:02 GMT</pubDate>
    <dc:creator>Wayne_Evans</dc:creator>
    <dc:date>2019-07-29T10:10:02Z</dc:date>
    <item>
      <title>SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26011#M5206</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is so low level and really context-related but I have been referencing both the SDLC as we been taught as meaning the "Software development lifecycle" but also been referencing ISO 27034 where the definition for SDLC is "Systems Development Life Cycle(s)".&amp;nbsp; This was raised in peer review in a document as slightly unclear.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are somewhat interchangeable conceptually perhaps but should ISC2 perhaps adopt the ISO definition instead or tweak it to make it not clash?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just added the acronym twice in my definitions table and expanded on first use in the paragraph to allow context.&lt;BR /&gt;&lt;BR /&gt;Wayne&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 10:10:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26011#M5206</guid>
      <dc:creator>Wayne_Evans</dc:creator>
      <dc:date>2019-07-29T10:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26013#M5207</link>
      <description>&lt;P&gt;I'd support the adoption of the ISO definition.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 12:06:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26013#M5207</guid>
      <dc:creator>wimremes</dc:creator>
      <dc:date>2019-07-29T12:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26015#M5209</link>
      <description>&lt;P&gt;The two terms are often used interchangeably in practice.&amp;nbsp; The plus side of using the system definition is that you'd consider a wider range of things; the hardware, OS, database, middleware, hosting, business processes and training.&amp;nbsp; Okay you could be just writing a Lambda function or a microservice, but often the undertaking will be non tivial.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 13:03:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26015#M5209</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-07-29T13:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26017#M5211</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/183830783"&gt;@Wayne_Evans&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I know this is so low level and really context-related but I have been referencing both the SDLC as we been taught as meaning the "Software development lifecycle" but also been referencing ISO 27034 where the definition for SDLC is "Systems Development Life Cycle(s)".&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;ISO/IEC 27034 is very useful for &lt;STRONG&gt;building and maturing an application security program&lt;/STRONG&gt;. The multi-part series represents much more than traditional thinking in terms of an SDLC, Its focus is upon refining the software engineering practices of an organization no matter how they define their SDLC processes. It would great if we could standardize on one definition, but it is not going to happen. &lt;U&gt;SDLC has simply become&amp;nbsp;an abstraction&lt;/U&gt;&amp;nbsp;that does not have to be defined within rigid constructs. What is more important is ensuring that security process are built into CI/CD processes of an organizations software lifecycle and then maturing them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;As a&amp;nbsp;&lt;A href="https://www.isc2.org/Certifications/CSSLP" target="_blank" rel="noopener"&gt;CSSLP&lt;/A&gt;&amp;nbsp;we need to move the bar forward beyond traditional SDLC thinking and begin to standardize on Agile and CI/CD.&lt;/STRONG&gt; Delivering quality (i.e., secure) software in a continuous delivery cycle should be the goal of our "SDLC" and whatever that means to an organization. Having said that ambiguous statement I would much rather &lt;STRONG&gt;retire the use of the term SDLC&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw. if anyone can't buy the standard then check out&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/securityengineering/sdl" target="_blank" rel="noopener"&gt;Microsoft's Security Development Lifecycle&lt;/A&gt; documentation because it is a reflection of it the standard.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 13:21:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26017#M5211</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-07-29T13:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26053#M5218</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&lt;STRONG&gt;As a&amp;nbsp;&lt;A href="https://www.isc2.org/Certifications/CSSLP" target="_blank" rel="noopener"&gt;CSSLP&lt;/A&gt;&amp;nbsp;we need to move the bar forward beyond traditional SDLC thinking and begin to standardize on Agile and CI/CD.&lt;/STRONG&gt; Delivering quality (i.e., secure) software in a continuous delivery cycle should be the goal of our "SDLC" and whatever that means to an organization. Having said that ambiguous statement I would much rather &lt;STRONG&gt;retire the use of the term SDLC&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw. if anyone can't buy the standard then check out&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/securityengineering/sdl" target="_blank" rel="noopener"&gt;Microsoft's Security Development Lifecycle&lt;/A&gt; documentation because it is a reflection of it the standard.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks for the link to Microsoft's document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 21:13:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26053#M5218</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-07-29T21:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26078#M5222</link>
      <description>&lt;P&gt;This discussion highlights a greater thought.&amp;nbsp; Like many other words, acronyms have multiple definitions. The speaker has the responsibility to include context that makes the intended definition clear.&amp;nbsp; This might include techniques such as linking to MS's Security page (thanks,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;!), referring to software or system in an earlier sentence, or even expanding the acronym on first use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although I generally agree with&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/269736147"&gt;@wimremes&lt;/a&gt;'s preference for deferring to standards, one also needs to consider that not all standards are aligned (e.g.&amp;nbsp;&lt;A href="https://en.wikipedia.org/wiki/ISO/IEC_12207" target="_blank" rel="noopener"&gt;ISO 12207&lt;/A&gt;&amp;nbsp;is "...Software Lifecycle...") and that focusing on just one definition, tends to disenfranchise the disciplines that default to the other definitions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 13:11:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26078#M5222</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-07-30T13:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: SDLC definition</title>
      <link>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26088#M5225</link>
      <description>&amp;gt; denbesten (Community Champion) posted a new reply in Member Support on&lt;BR /&gt;&lt;BR /&gt;&amp;gt; This discussion highlights a greater thought.&amp;nbsp; Like many other words, acronyms&lt;BR /&gt;&amp;gt; have multiple definitions. The speaker has the responsibility to include context&lt;BR /&gt;&amp;gt; that makes the intended definition clear.&lt;BR /&gt;&lt;BR /&gt;True.&lt;BR /&gt;&lt;BR /&gt;Ultimately, though, I have been amused by the discussion, as the main point of&lt;BR /&gt;SDLC, whether "software" or "system" (and regardless of either), is the&lt;BR /&gt;importance of method, structure, planning, assessment, and cyclical recurrence.&lt;BR /&gt;"Method and order!" as Hercule Poirot would say ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Great wits are sure to madness near allied. - John Dryden, 1681&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 30 Jul 2019 16:05:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/SDLC-definition/m-p/26088#M5225</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-07-30T16:05:57Z</dc:date>
    </item>
  </channel>
</rss>

