Supporting standards and resources
The remaining part of this chapter focuses on standards and resources that are useful but not mandatory. Organizations are encouraged to maintain a list of such resources to raise awareness among security practitioners and stay up to date on the latest publications of security best practices.
MITRE Common Weakness Enumeration (CWE)
MITRE compiles a list of software and hardware security weaknesses based on vulnerabilities that are periodically filed in the National Vulnerability Database (NVD) [72]. These weaknesses are grouped into classes for ease of searching. Every year, MITRE publishes the Top 25 CWEs [42] based on the vulnerabilities reported throughout the year:
Figure 4.9 – Snapshot of the Top 25 CWEs from 2022
As shown in Figure 4.9, CWE-787 remains in the Top 25 CWEs as the most common root cause of memory safety vulnerabilities that produce out-of-bound writes. Being aware of the Top 25 CWEs as...