<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1c1bb313e">
    <name type="corporate">
         <namePart>United States Government Publishing Office</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
              <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
         <role>
              <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
              <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
         <namePart>United States</namePart>
         <namePart>Commerce Department</namePart>
         <namePart>National Institute of Standards and Technology (NIST)</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
         <description>Government Organization</description>
    </name>
    <name type="personal">
         <namePart>Souppaya, Murugiah.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
         <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
         <collectionCode>GOVPUB</collectionCode>
         <category>Executive Agency Publications</category>
         <branch>executive</branch>
         <dateIngested>2023-10-27</dateIngested>
    </extension>
    <originInfo>
         <publisher>Commerce Department</publisher>
         <dateIssued encoding="w3cdtf">2022-02-03</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <note type="source content type">deposited</note>
         <digitalOrigin>born digital</digitalOrigin>
         <extent>36 digital object pages</extent>
    </physicalDescription>
    <classification authority="sudocs">C 13.</classification>
    <identifier type="uri">https://www.govinfo.gov/app/details/GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d</identifier>
    <identifier type="local">P0b002ee1c1bb313e</identifier>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST Special Publications</title>
        </titleInfo>
    </relatedItem>
    <identifier type="ILS system id">on1389890250</identifier>
    <identifier type="oclc">(OCoLC)1389890250</identifier>
    <recordInfo>
         <recordContentSource authority="marcorg">DGPO</recordContentSource>
         <recordCreationDate encoding="w3cdtf">2023-10-27</recordCreationDate>
         <recordChangeDate encoding="w3cdtf">2026-06-27</recordChangeDate>
         <recordIdentifier source="DGPO">GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d</recordIdentifier>
         <recordOrigin>machine generated</recordOrigin>
         <languageOfCataloging>
              <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    <accessCondition type="GPO scope determination">fdlp</accessCondition>
    <extension>
         <docClass>C13</docClass>
         <accessId>GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d</accessId>
         <uniqueId>2ea4989e5dc4ac2e4a07a44d2e5c075d</uniqueId>
         <ACCode>GOVPUB</ACCode>
         <fedPubName>NIST Special Publications</fedPubName>
         <field name="Note">NOTE: THE “DATE ISSUED” ABOVE MAY DEFAULT TO JANUARY 1ST OF A GIVEN YEAR. TO THE VIEW THE MOST ACCURATE DATE OF ISSUE, REVIEW THE TITLE PAGE OF THE PUBLICATION.</field>
         <description>This series includes proceedings of conferences sponsored by NIST, NIST annual reports, and other special publications appropriate to this grouping such as wall charts, pocket cards, and bibliographies.</description>
         <agency abbrev="NIST">National Institute of Standards and Technology</agency>
         <resultsLineTwoText>Commerce Department. National Institute of Standards and Technology. 2022</resultsLineTwoText>
         <dateIssued>2022-02-03</dateIssued>
    </extension>
    <location>
         <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d</url>
         <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d/pdf/GOVPUB-C13-2ea4989e5dc4ac2e4a07a44d2e5c075d.pdf</url>
    </location>
    <titleInfo>
         <title>Secure Software Development Framework (Ssdf) Version 1.1</title>
         <subTitle>Recommendations for Mitigating the Risk of Software Vulnerabilities</subTitle>
    </titleInfo>
    <subject>
         <topic>Acquisition of computer software</topic>
         <topic>Computer security--Software</topic>
         <topic>Computer software--Development</topic>
         <topic>Secure software development</topic>
         <topic>Secure Software Development Framework (SSDF), Secure software development practices</topic>
         <topic>Software development life cycle (SDLC)</topic>
         <topic>Software security</topic>
    </subject>
    <name type="personal">
         <namePart>Souppaya, Murugiah.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">creator</roleTerm>
        </role>
    </name>
    <name type="personal">
         <namePart>Souppaya, Murugiah.</namePart>
    </name>
    <name type="personal">
         <namePart>Scarfone, Karen.</namePart>
    </name>
    <name type="personal">
         <namePart>Dodson, Donna.</namePart>
    </name>
    <name type="corporate">
         <namePart>National Institute of Standards and Technology (U.S.)</namePart>
         <namePart>Information Technology Laboratory</namePart>
    </name>
    <originInfo>
         <place>
              <placeTerm authority="marccountry" type="code">mdu</placeTerm>
        </place>
         <publisher>U.S. Dept. of Commerce, National Institute of Standards and Technology</publisher>
         <dateIssued>2022-02-03.</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <extent>1 online resource (36 pages) : illustrations (color)</extent>
    </physicalDescription>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">technical report</genre>
    <language>
         <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </language>
    <abstract>Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF)   a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, mitigate the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities.</abstract>
    <note type="statement of responsibility">Murugiah Souppaya; Karen Scarfone; Donna Dodson.</note>
    <note>February 2022.</note>
    <note>Title from PDF title page (viewed January 4, 2023).</note>
    <note type="bibliography">Includes bibliographical references.</note>
    <note type="venue">Approved by the NIST Editorial Review Board on 2022-01-31</note>
    <note type="system details">Mode of access: World Wide Web.</note>
    <note type="system details">Systems requirements: Adobe Acrobat PDF reader.</note>
    <subject authority="lcsh">
         <topic>Acquisition of computer software</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Computer software--Development</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Computer security--Software</topic>
    </subject>
    <subject>
         <topic>Secure software development</topic>
    </subject>
    <subject>
         <topic>Secure Software Development Framework (SSDF), Secure software development practices</topic>
    </subject>
    <subject>
         <topic>Software development life cycle (SDLC)</topic>
    </subject>
    <subject>
         <topic>Software security</topic>
    </subject>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST special publication; NIST special pub; NIST SP; 800-218</title>
        </titleInfo>
    </relatedItem>
    <location>
         <url displayLabel="electronic resource" usage="primary display">https://doi.org/10.6028/NIST.SP.800-218</url>
    </location>
    <titleInfo type="alternative">
         <title>Secure Software Development Framework (SSDF) version 1.1</title>
         <subTitle>recommendations for mitigating the risk of software vulnerabilities</subTitle>
    </titleInfo>
    <extension>
         <searchTitle>
              <title>Secure Software Development Framework (SSDF) version 1.1</title>
              <subTitle>recommendations for mitigating the risk of software vulnerabilities</subTitle>
        </searchTitle>
    </extension>
</mods>