The Secure Software Development Lifecycle (SSDLC) embeds security activities across every phase of development, from requirements and design to deployment and operations. Its goal is to detect risks early and prevent vulnerabilities rather than fix them later. It includes processes, roles, tools, and reviews to continuously secure software.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
A secure software development lifecycle embeds security activities in every phase of software development.
The approach grew from recognizing that security risks must be addressed systematically early in development. OWASP SAMM provides a maturity model for software assurance practices.
An SSDLC adds security requirements, threat analysis, secure implementation, testing, and continuous improvement to planning, development, release, and operations. Earlier risk discovery reduces remediation effort and downstream cost; the whole team shares responsibility.
Security is embedded as a continuous concern in the development lifecycle.
Requirements, reviews, tests, and feedback accompany every lifecycle phase.
Teams improve maturity and practices according to their context.
SSDLC helps teams manage security risk predictably and connect security work with delivery, quality, and operations.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.