The security goal of a development team is to deliver secure design and implementation. Based on OWASP SAMM practices, there are three key aspects to consider during the construction phase:
- Threat assessment
- Security requirements
- Secure architecture
Although design and implementation review is normally also part of the development team's activities, we will take these into consideration in further discussions.