Become a partner

Towards Establishing High Standards for Secure Software in Public Procurement Processes

/ Lecture
The importance of high security standards of software products and their source code in public procurement processes continues to grow. It is very important to ensure that any software delivered as a result of a public procurement process adheres to high standards in application security. Software in the public sector has consistently high requirements with regard to confidentiality, integrity and availability. Checkmarx has long standing experience in providing methodologies and best practices for secure development as well as the technical solution to check the security of source code and open source components that are included in a software product provided as a result of a public procurement process. Two key aspect are (1) to assess the maturity of the secure software development process of the supplier and how the supplier can provide evidence that its software development process follows high security standards in the development process and furthermore (2) that suppliers provide documentation of the results of technical solutions/tools used to verify the security of the software and its source code. In this talk I will give an introduction on best practices to follow and our proposed approach from long standing experience in application security.


Carsten Huth

Carsten has over 15 years of experience in InfoSec and over 10 years of experience in application security. He has carried out numerous AppSec program rollouts and deployments as a professional services consultant becoming a practice principal and managing a team of software security consultants across Europe. When joining Checkmarx in 2016, Carsten initially worked as the first Technical Account Manager (TAM), managing the largest accounts of Checkmarx in EMEA. Shortly after joining Checkmarx, Carsten started building the team of technical account managers around him and a year later also a team of AppSec advisors. Carsten has contributed to the OWASP OpenSAMM standard and has presented at various application security conferences.
See more info about the speaker

Recommendation speakers

Páčil sa ti článok? Zdieľaj ho a povedz o ňom aj ostatným
Nastavenie súborov cookies