Invention Grant
- Patent Title: Security risk identification in a secure software lifecycle
-
Application No.: US15784072Application Date: 2017-10-13
-
Publication No.: US10706156B2Publication Date: 2020-07-07
- Inventor: Nishchal Bhalla , Rohit Kumar Sethi , Ramanan Sivaranjan , Ehsan Foroughi , Geoffrey Charles Whittington
- Applicant: 1230604 BC Ltd.
- Main IPC: G06F8/00
- IPC: G06F8/00 ; G06F8/10 ; G06F8/20 ; G06F8/70 ; G06F16/23 ; G06F21/00 ; G06F21/50 ; G06F21/57 ; G06F21/55

Abstract:
A system and method for security risk identification in a secure software lifecycle. A knowledge database has a plurality of security elements which are identified for a particular software application depending on software environment and prioritized in a task list. Code vulnerabilities are identified using code scanners, with security requirements updated based on identified vulnerabilities, lack of vulnerabilities for weaknesses covered by a code scanner, potential weaknesses not adequately covered by code scanners, and software environment changes.
Public/Granted literature
- US20190114435A1 SECURITY RISK IDENTIFICATION IN A SECURE SOFTWARE LIFECYCLE Public/Granted day:2019-04-18
Information query