当前位置:首页 >英文主页 >中英对照 > 中译版报告详情

Veracode:2025年度全球软件安全状况报告:成熟度新视角(中译版)(35页).pdf

上传人: Y**** 编号:710362 2025-05-29 35页 1.47MB

下载:

1、2025 STATE OFA NEW VIEW OF MATURITYContents03 Opening Letter04 Executive SummaryKey Findings07 15 Years of Special SoSS09 State of Software Security in 2025Finding FlawsFixing FlawsFighting Debt19 Comparing Software Security Program PerformanceFlaw PrevalenceFix CapacityFix SpeedDebt PrevalenceOpen-

2、Source Debt31 Conclusions&Recommendations 34 Methodology2025 STATE OF SOFTWARE SECURITY:A NEW VIEW OF MATURITY2Our research drives our own software security measures,and this year,in our 15th volume of this report,we seek to discover trends about where the most risk resides and what metrics can be u

3、sed to gauge progress against it.Plus,we want to compare program performance of leading and lagging organizations using these metrics.The gaps between the top 25%and bottom 25%are fascinating.Ultimately,realizing progress and maturity in software security requires a risk-based perspective.It takes f

4、ocusing on the downside risks that matter in your context and the actions that create continuous feedback loops to see and remediate risk in an ongoing fashion.This is easier said than done,so we hope you find the insights and guidance in this report as helpful as we have for improving security post

5、ure by adaptively securing mission-critical software in the artificial intelligence(AI)era.Sincerely,Opening letterNiels TanisSenior Principal Security ResearcherSohail Iqbal Chief Information Security Officer Chris Wysopal Chief Security Evangelist2025 STATE OF SOFTWARE SECURITY:A NEW VIEW OF MATUR

6、ITY3Executive Summary2025 STATE OF SOFTWARE SECURITY:A NEW VIEW OF MATURITY4In 2025,organizations face increasing threats to their software.The exploitation of vulnerabilities as the critical path to initiate a breach“almost tripled(180%increase)in the last year,”according to the Verizon 2024 Data B

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文是2025年软件安全状态报告,主要内容包括: 1. 软件安全漏洞普遍存在,80%的应用程序存在至少一个安全漏洞。 2. 应用程序通过OWASP Top 10和CWE Top 25测试的比例稳步下降,高严重性漏洞的普遍性在过去十年中减半。 3. 安全债务正在增加,74.2%的组织存在安全债务,其中49.9%的组织存在关键安全债务。 4. 修复漏洞的速度较慢,平均需要5个月才能修复一半的安全漏洞。 5. 开源代码中的安全漏洞占所有安全债务的11%,但关键安全债务的70%来自第三方代码。 6. 建议通过自动化和反馈循环在SDLC中实现可见性和集成,以及通过关联和上下文化发现来减少风险和最少的努力来偿还积压。
软件安全债务如何影响组织? 如何有效管理开源代码中的安全漏洞? 人工智能在软件安全中的应用有哪些?
客服
商务合作
小程序
服务号
折叠