From the course: Static Application Security Testing

Unlock the full course today

Join today to access over 24,900 courses taught by industry experts.

Change control policy

Change control policy

- [Instructor] Building security into your project plans is a great first step, but you're only getting started. You'll also need to develop an effective communication plan. And when I put together my own communication plans, I don't go for anything fancy or complicated. Your goals should be rock simple, keep everyone on the same page. You need to spend time on a communication plan for your static application security testing activities because they'll have some level of impact on everyone involved. Testing can impact schedules and deadlines. If flaws must be remediated before subsequent development can occur, then everyone impacted will need to know when one of these flaws is discovered and when it's going to be remediated. Testing also requires resources. Whether it's a developer, an analyst or a security professional someone needs to run those tests, they need to interpret those results, and they need to provide…

Contents