Secure Coding Practice Guidelines

UC Berkeley security policy mandates compliance with Minimum Security Standard for Electronic Information for devices handling covered data. The recommendations below are provided as optional guidance for MSSEI Sections 12.4 Secure Software Development and 3.1 Information Security Training requirements.

Requirement

Secure coding practices, including security training and reviews, are required for network accessible software developed for any purpose, regardless of the Protection Level of the information involved. Additionally, secure coding training is required for people developing network accessible software/applications.

Description of Risk

Unsafe coding practices result in costly vulnerabilities in application software that leads to the theft of sensitive data.

Recommendations

For applications to be designed and implemented with proper security requirements, secure coding practices and a focus on security risks must be integrated into day-to-day operations and the development processes. Application developers must complete secure coding requirements regardless of the device used for programming.

Application Security Training

A critical first step to develop a secure application is an effective training plan that allows developers to learn important secure coding principles , such as those described in the OWASP Developer Guide.

While OWASP (Open Web Application Security Project) specifically references web applications, the secure coding principles outlined above should be applied to non-web applications as well. Please refer to OWASP Top10: The Ten Most Critical Web Application Security Risks to see a description of each secure coding principle.  

Listed below are examples of training courses that can be used to gain proficiency in secure coding principles (update in progress):

Alternately, relevant books and reading material can also be used to develop proficiency in secure coding principles, provided that sufficient time is allocated to staff for self-study.

Secure Coding Practices

Secure coding practices must be incorporated into all life cycle stages of an application development process. The following minimum set of secure coding practices should be implemented when developing and deploying covered applications:

  1. Formalize and document the software development life cycle (SDLC) processes to incorporate a major component of a development process:

While there is no campus standard or prescriptive model for SDLC methodologies, the resource proprietor and resource custodian should ensure the above major components of a development process are defined in respect to the adopted development methodology, which could be traditional waterfall model, agile or other models.

  1. Integrate secure coding practices into SDLC components by providing a general description of how the secure coding principles are addressed in Architecture and Design documents. If a secure coding principle is not applicable to the project, this should be explicitly documented along with a brief explanation.
     
  2. Perform automated application security testing as part of the overall application testing process. See "Relevant Campus Services" below for details of automated application security testing service offered by ISO.
     
  3. Development and testing environments should redact all sensitive data or use de-identified data.

Relevant Campus Services

ISO Web Application Security Testing Program

The Information Security Office has partnered with the School of Information's (I School) Master of Information and Cybersecurity (MICS) Program to offer web application security testing of UC Berkeley web applications by MICS students. Priority is given to web applications handling P4 and P3 data; however, all UC Berkeley web applications are encouraged to apply. For details of the service, please visit the service overview page.

Code Review

Additional Resources