The invention discloses a research, development and operation method and device for security left shift, and relates to the field of
software development processes and
security management.The method comprises the steps that a security demand baseline is established in the
demand analysis stage, security demands and business demands are fused, and risk protection measures are determined; security architecture
design review is carried out in the architecture
design stage, and a security team carries out
threat modeling on the
system architecture and carries out one-
ticket negative right; in the
code development stage, code specifications,
open source component vulnerabilities and logic risks are scanned in real time through a static code analysis tool, and a code security closed-loop management mechanism is established; in the compiling and constructing stage,
code review and component
list filing are implemented, a security review report is formed by combining a dynamic
penetration test and a running flow test, and a security strategy is updated through a
continuous monitoring mechanism to deal with new threats. Security practice can be systematically integrated in the early stage of the
software development life cycle, and the later
vulnerability repair cost is remarkably reduced.