• Laser@feddit.de
    link
    fedilink
    arrow-up
    0
    ·
    9 months ago

    For all the criticism it gets, this is something that Common Criteria at EAL 3 and higher covers, and if your company can’t ensure secure development of a product, the product doesn’t get certified. At least my scheme is always very strict with life cycle aspects, and if you’re not getting a certificate for a market it’s required in, that’s money lost, and a huge motivator for management to implement changes.