SCW Icons
hero bg no divider
Blog

NISTで行動を起こす:サイバー防衛の未来に関する人間主導の立場

マティアス・マドゥ博士
Published Jun 21, 2021
Last updated on Mar 10, 2026

The recent cybersecurity Executive Order from the Biden Administration has certainly got the security industry talking, especially those who are looking to win over developers to the importance of applying secure coding best practices in their day-to-day work. For the first time, developers who are working on software in use by the federal government must have verified security skills, as well as adherence to new, evolved guidelines. 

This marks a positive change in the cyber defense status quo, and finally makes adequate upskilling of developers part of the conversation. While these policies are US government-centric, they offer a global opportunity for organizations to address and upgrade current security standards, everything from developers to security analysis of software supply chains. 

NIST recently sought public comment to inform their next updates to HIPAA legislation, among others, and this was an unmissable opportunity for us to pool our company expertise into positioning papers that can help inform a safer, and more effective, human-led approach to cybersecurity that will help organizations leverage their teams for greater outcomes. 

As an expert-driven organization, we are fortunate to have some of the most dedicated and accomplished cybersecurity professionals working with us, including Ph.D. candidate Pieter de Cremer, and Dr. Brian Chess, who is part of our Technical Advisory Board. The three of us put our heads together to formally submit positioning papers to NIST, calling out ways our approach to developer upskilling and preventative security at the software creation stage could positively impact cybersecurity standards going forward. 

A secure development pathway, paved for developers

Vulnerability scanning tools, monitoring and other forms of security automation are increasingly prevalent, and they feature in both the new Executive Order, as well as within NIST guidelines. They are an increasingly essential part of a modern security program, but history and the present show that scanning tools in particular certainly find vulnerabilities in software with ever-increasing efficiency, yet this alone has no effect on reducing them, or, indeed, improving security from the start. 

A cumbersome tech stack that is distracting and slows down the developer workflow is one of the fundamental reasons that developers disengage with security and view it in a negative light. However, if developers had a paved pathway for secure development, one that was customized to suit not just the technology, but also languages, frameworks, and project-specific development objectives, then embedding security into the development process from the beginning - with as little disruption to their productivity as possible - is an ideal that would result in significant reduction in common vulnerabilities over time. 


To read our NIST positioning paper in full, download it now:

Banner that says paper: promote a paved path secure development methodology
Download our full position paper as proposed to NIST.

Certification framework for secure development practices: The (current) missing link

To date, there is no formal certification to verifying secure coding skills and best practices. This has been an industry oversight for a long time, and it’s our position that this is essential for the future of improved cyber defense and secure development. 

We know there are many forms of security training targeting developers, but if the volume of large-scale data breaches, cyberattacks, and poor quality code out there is any indication, it’s not creating security-aware developers, and they are not being equipped with the knowledge to make a dent in a problem that is only getting worse. 

Developer upskilling requires tools and education that is day-job relevant, contextual, bite-sized (yet frequent), and allows them to build upon existing knowledge in the languages and frameworks they actually use. Generic training does not suffice, and this needs to be made abundantly clear in legislation and industry bodies such as NIST. 

The NICE Framework is more than suitable to build out comprehensive certification guidelines that actively use methodologies that work, and are of most interest and relevance to developers, and their work. Aligning with this recognized institutional framework helps to standardize practices that truly make a difference, and provides more concrete pathways for organizations to follow. 


To read our second NIST positioning paper in full, download it now:

Banner that says paper: create a certification framework for secure development practices
Download our full position paper as proposed to NIST.


The people factor in cybersecurity is often forgotten, and it’s time we worked towards human solutions for human problems such as recurrent common vulnerabilities. Decades-old bugs should no longer trip us up, but it will take the backing of global governments to change the status quo and provide measurable, positive impact. 

Are you ready to certify your developers? You’ve come to the right place. Check out our Learning Platform today.

リソースを表示
リソースを表示

バイデン政権による最近のサイバーセキュリティ大統領令により、セキュリティ業界、特に日常業務にセキュアコーディングのベストプラクティスを適用することの重要性を開発者に理解してもらいたいと考えているセキュリティ業界は注目を集めています。

もっと興味がありますか?

マティアス・マドゥ博士は、セキュリティ専門家、研究者、CTO、セキュア・コード・ウォリアーの共同創設者です。Matias はゲント大学で静的分析ソリューションを中心にアプリケーションセキュリティの博士号を取得しました。その後、米国のFortifyに入社し、開発者が安全なコードを書くのを手伝わずに、コードの問題を検出するだけでは不十分であることに気づきました。これがきっかけで、開発者を支援し、セキュリティの負担を軽減し、顧客の期待を超える製品を開発するようになりました。Team Awesome の一員としてデスクにいないときは、RSA カンファレンス、BlackHat、DefCon などのカンファレンスでプレゼンテーションを行うステージでのプレゼンテーションを楽しんでいます。

learn more

Secure Code Warriorは、ソフトウェア開発ライフサイクル全体にわたってコードを保護し、サイバーセキュリティを最優先とする文化を築くお手伝いをします。アプリケーションセキュリティマネージャ、開発者、CISO、またはセキュリティ関係者のいずれであっても、安全でないコードに関連するリスクを軽減するお手伝いをします。

デモを予約
シェア:
linkedin brandsSocialx logo
著者
マティアス・マドゥ博士
Published Jun 21, 2021

マティアス・マドゥ博士は、セキュリティ専門家、研究者、CTO、セキュア・コード・ウォリアーの共同創設者です。Matias はゲント大学で静的分析ソリューションを中心にアプリケーションセキュリティの博士号を取得しました。その後、米国のFortifyに入社し、開発者が安全なコードを書くのを手伝わずに、コードの問題を検出するだけでは不十分であることに気づきました。これがきっかけで、開発者を支援し、セキュリティの負担を軽減し、顧客の期待を超える製品を開発するようになりました。Team Awesome の一員としてデスクにいないときは、RSA カンファレンス、BlackHat、DefCon などのカンファレンスでプレゼンテーションを行うステージでのプレゼンテーションを楽しんでいます。

Matiasは、15年以上のソフトウェアセキュリティの実務経験を持つ研究者および開発者です。フォーティファイ・ソフトウェアや自身の会社であるセンセイ・セキュリティなどの企業向けにソリューションを開発してきました。マティアスはキャリアを通じて、複数のアプリケーションセキュリティ研究プロジェクトを主導し、それが商用製品につながり、10件以上の特許を取得しています。デスクから離れているときには、マティアスは上級アプリケーション・セキュリティ・トレーニング・コースの講師を務め、RSA Conference、Black Hat、DefCon、BSIMM、OWASP AppSec、BruConなどのグローバルカンファレンスで定期的に講演を行っています。

マティアスはゲント大学でコンピューター工学の博士号を取得し、そこでアプリケーションの内部動作を隠すためのプログラムの難読化によるアプリケーションセキュリティを学びました。

シェア:
linkedin brandsSocialx logo

The recent cybersecurity Executive Order from the Biden Administration has certainly got the security industry talking, especially those who are looking to win over developers to the importance of applying secure coding best practices in their day-to-day work. For the first time, developers who are working on software in use by the federal government must have verified security skills, as well as adherence to new, evolved guidelines. 

This marks a positive change in the cyber defense status quo, and finally makes adequate upskilling of developers part of the conversation. While these policies are US government-centric, they offer a global opportunity for organizations to address and upgrade current security standards, everything from developers to security analysis of software supply chains. 

NIST recently sought public comment to inform their next updates to HIPAA legislation, among others, and this was an unmissable opportunity for us to pool our company expertise into positioning papers that can help inform a safer, and more effective, human-led approach to cybersecurity that will help organizations leverage their teams for greater outcomes. 

As an expert-driven organization, we are fortunate to have some of the most dedicated and accomplished cybersecurity professionals working with us, including Ph.D. candidate Pieter de Cremer, and Dr. Brian Chess, who is part of our Technical Advisory Board. The three of us put our heads together to formally submit positioning papers to NIST, calling out ways our approach to developer upskilling and preventative security at the software creation stage could positively impact cybersecurity standards going forward. 

A secure development pathway, paved for developers

Vulnerability scanning tools, monitoring and other forms of security automation are increasingly prevalent, and they feature in both the new Executive Order, as well as within NIST guidelines. They are an increasingly essential part of a modern security program, but history and the present show that scanning tools in particular certainly find vulnerabilities in software with ever-increasing efficiency, yet this alone has no effect on reducing them, or, indeed, improving security from the start. 

A cumbersome tech stack that is distracting and slows down the developer workflow is one of the fundamental reasons that developers disengage with security and view it in a negative light. However, if developers had a paved pathway for secure development, one that was customized to suit not just the technology, but also languages, frameworks, and project-specific development objectives, then embedding security into the development process from the beginning - with as little disruption to their productivity as possible - is an ideal that would result in significant reduction in common vulnerabilities over time. 


To read our NIST positioning paper in full, download it now:

Banner that says paper: promote a paved path secure development methodology
Download our full position paper as proposed to NIST.

Certification framework for secure development practices: The (current) missing link

To date, there is no formal certification to verifying secure coding skills and best practices. This has been an industry oversight for a long time, and it’s our position that this is essential for the future of improved cyber defense and secure development. 

We know there are many forms of security training targeting developers, but if the volume of large-scale data breaches, cyberattacks, and poor quality code out there is any indication, it’s not creating security-aware developers, and they are not being equipped with the knowledge to make a dent in a problem that is only getting worse. 

Developer upskilling requires tools and education that is day-job relevant, contextual, bite-sized (yet frequent), and allows them to build upon existing knowledge in the languages and frameworks they actually use. Generic training does not suffice, and this needs to be made abundantly clear in legislation and industry bodies such as NIST. 

The NICE Framework is more than suitable to build out comprehensive certification guidelines that actively use methodologies that work, and are of most interest and relevance to developers, and their work. Aligning with this recognized institutional framework helps to standardize practices that truly make a difference, and provides more concrete pathways for organizations to follow. 


To read our second NIST positioning paper in full, download it now:

Banner that says paper: create a certification framework for secure development practices
Download our full position paper as proposed to NIST.


The people factor in cybersecurity is often forgotten, and it’s time we worked towards human solutions for human problems such as recurrent common vulnerabilities. Decades-old bugs should no longer trip us up, but it will take the backing of global governments to change the status quo and provide measurable, positive impact. 

Are you ready to certify your developers? You’ve come to the right place. Check out our Learning Platform today.

リソースを表示
リソースを表示

レポートをダウンロードするには、以下のフォームに記入してください

当社の製品および/または関連するセキュアコーディングのトピックに関する情報を送信する許可をお願いします。当社は、お客様の個人情報を常に細心の注意を払って取り扱い、マーケティング目的で他社に販売することは決してありません。

送信
scw success icon
scw error icon
フォームを送信するには、「アナリティクス」クッキーを有効にしてください。設定が完了したら、再度無効にしても構いません。

The recent cybersecurity Executive Order from the Biden Administration has certainly got the security industry talking, especially those who are looking to win over developers to the importance of applying secure coding best practices in their day-to-day work. For the first time, developers who are working on software in use by the federal government must have verified security skills, as well as adherence to new, evolved guidelines. 

This marks a positive change in the cyber defense status quo, and finally makes adequate upskilling of developers part of the conversation. While these policies are US government-centric, they offer a global opportunity for organizations to address and upgrade current security standards, everything from developers to security analysis of software supply chains. 

NIST recently sought public comment to inform their next updates to HIPAA legislation, among others, and this was an unmissable opportunity for us to pool our company expertise into positioning papers that can help inform a safer, and more effective, human-led approach to cybersecurity that will help organizations leverage their teams for greater outcomes. 

As an expert-driven organization, we are fortunate to have some of the most dedicated and accomplished cybersecurity professionals working with us, including Ph.D. candidate Pieter de Cremer, and Dr. Brian Chess, who is part of our Technical Advisory Board. The three of us put our heads together to formally submit positioning papers to NIST, calling out ways our approach to developer upskilling and preventative security at the software creation stage could positively impact cybersecurity standards going forward. 

A secure development pathway, paved for developers

Vulnerability scanning tools, monitoring and other forms of security automation are increasingly prevalent, and they feature in both the new Executive Order, as well as within NIST guidelines. They are an increasingly essential part of a modern security program, but history and the present show that scanning tools in particular certainly find vulnerabilities in software with ever-increasing efficiency, yet this alone has no effect on reducing them, or, indeed, improving security from the start. 

A cumbersome tech stack that is distracting and slows down the developer workflow is one of the fundamental reasons that developers disengage with security and view it in a negative light. However, if developers had a paved pathway for secure development, one that was customized to suit not just the technology, but also languages, frameworks, and project-specific development objectives, then embedding security into the development process from the beginning - with as little disruption to their productivity as possible - is an ideal that would result in significant reduction in common vulnerabilities over time. 


To read our NIST positioning paper in full, download it now:

Banner that says paper: promote a paved path secure development methodology
Download our full position paper as proposed to NIST.

Certification framework for secure development practices: The (current) missing link

To date, there is no formal certification to verifying secure coding skills and best practices. This has been an industry oversight for a long time, and it’s our position that this is essential for the future of improved cyber defense and secure development. 

We know there are many forms of security training targeting developers, but if the volume of large-scale data breaches, cyberattacks, and poor quality code out there is any indication, it’s not creating security-aware developers, and they are not being equipped with the knowledge to make a dent in a problem that is only getting worse. 

Developer upskilling requires tools and education that is day-job relevant, contextual, bite-sized (yet frequent), and allows them to build upon existing knowledge in the languages and frameworks they actually use. Generic training does not suffice, and this needs to be made abundantly clear in legislation and industry bodies such as NIST. 

The NICE Framework is more than suitable to build out comprehensive certification guidelines that actively use methodologies that work, and are of most interest and relevance to developers, and their work. Aligning with this recognized institutional framework helps to standardize practices that truly make a difference, and provides more concrete pathways for organizations to follow. 


To read our second NIST positioning paper in full, download it now:

Banner that says paper: create a certification framework for secure development practices
Download our full position paper as proposed to NIST.


The people factor in cybersecurity is often forgotten, and it’s time we worked towards human solutions for human problems such as recurrent common vulnerabilities. Decades-old bugs should no longer trip us up, but it will take the backing of global governments to change the status quo and provide measurable, positive impact. 

Are you ready to certify your developers? You’ve come to the right place. Check out our Learning Platform today.

オンラインセミナーを見る
始めよう
learn more

以下のリンクをクリックして、このリソースのPDFをダウンロードしてください。

Secure Code Warriorは、ソフトウェア開発ライフサイクル全体にわたってコードを保護し、サイバーセキュリティを最優先とする文化を築くお手伝いをします。アプリケーションセキュリティマネージャ、開発者、CISO、またはセキュリティ関係者のいずれであっても、安全でないコードに関連するリスクを軽減するお手伝いをします。

レポートを表示デモを予約
PDF をダウンロード
リソースを表示
シェア:
linkedin brandsSocialx logo
もっと興味がありますか?

シェア:
linkedin brandsSocialx logo
著者
マティアス・マドゥ博士
Published Jun 21, 2021

マティアス・マドゥ博士は、セキュリティ専門家、研究者、CTO、セキュア・コード・ウォリアーの共同創設者です。Matias はゲント大学で静的分析ソリューションを中心にアプリケーションセキュリティの博士号を取得しました。その後、米国のFortifyに入社し、開発者が安全なコードを書くのを手伝わずに、コードの問題を検出するだけでは不十分であることに気づきました。これがきっかけで、開発者を支援し、セキュリティの負担を軽減し、顧客の期待を超える製品を開発するようになりました。Team Awesome の一員としてデスクにいないときは、RSA カンファレンス、BlackHat、DefCon などのカンファレンスでプレゼンテーションを行うステージでのプレゼンテーションを楽しんでいます。

Matiasは、15年以上のソフトウェアセキュリティの実務経験を持つ研究者および開発者です。フォーティファイ・ソフトウェアや自身の会社であるセンセイ・セキュリティなどの企業向けにソリューションを開発してきました。マティアスはキャリアを通じて、複数のアプリケーションセキュリティ研究プロジェクトを主導し、それが商用製品につながり、10件以上の特許を取得しています。デスクから離れているときには、マティアスは上級アプリケーション・セキュリティ・トレーニング・コースの講師を務め、RSA Conference、Black Hat、DefCon、BSIMM、OWASP AppSec、BruConなどのグローバルカンファレンスで定期的に講演を行っています。

マティアスはゲント大学でコンピューター工学の博士号を取得し、そこでアプリケーションの内部動作を隠すためのプログラムの難読化によるアプリケーションセキュリティを学びました。

シェア:
linkedin brandsSocialx logo

The recent cybersecurity Executive Order from the Biden Administration has certainly got the security industry talking, especially those who are looking to win over developers to the importance of applying secure coding best practices in their day-to-day work. For the first time, developers who are working on software in use by the federal government must have verified security skills, as well as adherence to new, evolved guidelines. 

This marks a positive change in the cyber defense status quo, and finally makes adequate upskilling of developers part of the conversation. While these policies are US government-centric, they offer a global opportunity for organizations to address and upgrade current security standards, everything from developers to security analysis of software supply chains. 

NIST recently sought public comment to inform their next updates to HIPAA legislation, among others, and this was an unmissable opportunity for us to pool our company expertise into positioning papers that can help inform a safer, and more effective, human-led approach to cybersecurity that will help organizations leverage their teams for greater outcomes. 

As an expert-driven organization, we are fortunate to have some of the most dedicated and accomplished cybersecurity professionals working with us, including Ph.D. candidate Pieter de Cremer, and Dr. Brian Chess, who is part of our Technical Advisory Board. The three of us put our heads together to formally submit positioning papers to NIST, calling out ways our approach to developer upskilling and preventative security at the software creation stage could positively impact cybersecurity standards going forward. 

A secure development pathway, paved for developers

Vulnerability scanning tools, monitoring and other forms of security automation are increasingly prevalent, and they feature in both the new Executive Order, as well as within NIST guidelines. They are an increasingly essential part of a modern security program, but history and the present show that scanning tools in particular certainly find vulnerabilities in software with ever-increasing efficiency, yet this alone has no effect on reducing them, or, indeed, improving security from the start. 

A cumbersome tech stack that is distracting and slows down the developer workflow is one of the fundamental reasons that developers disengage with security and view it in a negative light. However, if developers had a paved pathway for secure development, one that was customized to suit not just the technology, but also languages, frameworks, and project-specific development objectives, then embedding security into the development process from the beginning - with as little disruption to their productivity as possible - is an ideal that would result in significant reduction in common vulnerabilities over time. 


To read our NIST positioning paper in full, download it now:

Banner that says paper: promote a paved path secure development methodology
Download our full position paper as proposed to NIST.

Certification framework for secure development practices: The (current) missing link

To date, there is no formal certification to verifying secure coding skills and best practices. This has been an industry oversight for a long time, and it’s our position that this is essential for the future of improved cyber defense and secure development. 

We know there are many forms of security training targeting developers, but if the volume of large-scale data breaches, cyberattacks, and poor quality code out there is any indication, it’s not creating security-aware developers, and they are not being equipped with the knowledge to make a dent in a problem that is only getting worse. 

Developer upskilling requires tools and education that is day-job relevant, contextual, bite-sized (yet frequent), and allows them to build upon existing knowledge in the languages and frameworks they actually use. Generic training does not suffice, and this needs to be made abundantly clear in legislation and industry bodies such as NIST. 

The NICE Framework is more than suitable to build out comprehensive certification guidelines that actively use methodologies that work, and are of most interest and relevance to developers, and their work. Aligning with this recognized institutional framework helps to standardize practices that truly make a difference, and provides more concrete pathways for organizations to follow. 


To read our second NIST positioning paper in full, download it now:

Banner that says paper: create a certification framework for secure development practices
Download our full position paper as proposed to NIST.


The people factor in cybersecurity is often forgotten, and it’s time we worked towards human solutions for human problems such as recurrent common vulnerabilities. Decades-old bugs should no longer trip us up, but it will take the backing of global governments to change the status quo and provide measurable, positive impact. 

Are you ready to certify your developers? You’ve come to the right place. Check out our Learning Platform today.

目次

PDF をダウンロード
リソースを表示
もっと興味がありますか?

マティアス・マドゥ博士は、セキュリティ専門家、研究者、CTO、セキュア・コード・ウォリアーの共同創設者です。Matias はゲント大学で静的分析ソリューションを中心にアプリケーションセキュリティの博士号を取得しました。その後、米国のFortifyに入社し、開発者が安全なコードを書くのを手伝わずに、コードの問題を検出するだけでは不十分であることに気づきました。これがきっかけで、開発者を支援し、セキュリティの負担を軽減し、顧客の期待を超える製品を開発するようになりました。Team Awesome の一員としてデスクにいないときは、RSA カンファレンス、BlackHat、DefCon などのカンファレンスでプレゼンテーションを行うステージでのプレゼンテーションを楽しんでいます。

learn more

Secure Code Warriorは、ソフトウェア開発ライフサイクル全体にわたってコードを保護し、サイバーセキュリティを最優先とする文化を築くお手伝いをします。アプリケーションセキュリティマネージャ、開発者、CISO、またはセキュリティ関係者のいずれであっても、安全でないコードに関連するリスクを軽減するお手伝いをします。

デモを予約[ダウンロード]
シェア:
linkedin brandsSocialx logo
リソースハブ

始めるためのリソース

その他の投稿
リソースハブ

始めるためのリソース

その他の投稿