Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST Secure Software Development Framework (SSDF)

NIST Secure Software Development Framework (SSDF)

The NIST Secure Software Development Framework, or NIST SP 800-218, is a set of practices employed by NIST to be embedded in the development cycle of software. The framework promotes the concept of “security-by-design,” which supports developers in discovering and solving vulnerabilities at every stage of development. This approach reduces the chances that released software harbors undiscovered vulnerabilities and actively addresses the root causes of those vulnerabilities to make the software more resilient.

There are four core activities of the SSDF:

  1. Prepare the Organization: It focuses on establishing a culture that is security-oriented and preparing training programs for the security teams based on security best practices.
  2. Protect the Software: This phase of the handbook tells organizations what should be done to protect the software throughout its lifecycle and includes secure coding practices, code review, and more.
  3. Produce Well-Secured Software: In this phase, defects are discovered and fixed at design stage and tested continuously at the time of development.
  4. Address Vulnerabilities: This involves patch management and incident responses in a way that every vulnerability found can be solved and addressed to maintain the integrity and security of the software even after release.

The SSDF accommodates other NIST frameworks into its system to thereby create a holistic approach for software security.

Additional reading

Honest Vanta Review: What It Gets Right and Where It Falls Short

TL;DR Vanta is a compliance automation platform best suited for startups and mid-market teams pursuing SOC 2, ISO 27001, HIPAA, and similar frameworks. Pricing typically ranges from $10K–$15K/year for startups and $30K–$80K+ for larger teams, with quote-based annual contracts. If you’ve been evaluating compliance automation tools, Vanta has likely made it into your list. It’s…

FedRAMP For SaaS: A How-To Guide

Seizing new opportunities, expanding horizons, and delighting your existing customers is what fuels growth for SaaS businesses and we are positive that it is the same for your organization too.  The value of the stake increases as you set your sights on bigger and better prospects. One such high-stake prospect is the federal government of…

UK GDPR vs EU GDPR: Key Differences Explained

Key Points Introduction If you run a cloud-hosted company that collects customer data in the United Kingdom (UK), you would have heard about the General Data Protection Regulation (GDPR).  GDPR is regarded as the most important data protection law in the European Union (EU) and the United Kingdom (UK). The primary purpose of UK privacy…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.