Standards provide the basis for demonstrating compliance with laws, policies, and regulatory guidelines.

Black Duck DevSecOps tools and services can help organizations comply with laws, regulatory guidance, policies, and standards related to application security (AppSec), software quality, data protection, and privacy. Avoid exploits by finding and fixing weaknesses and vulnerabilities using DevSecOps tools that provide detailed reports listing the specific rules and categories of each standard that the tools address.

To help raise the bar for software security and stay informed about the latest security issues, Black Duck employees serve or have served as subject matter experts for the committees, boards, working groups, programs, and projects related to AppSec standards, policies, and regulatory guidelines.

Standards and Policies Image

Automotive Industry Action Group (AIAG)

Standards and Policies Image

Automotive Information Sharing and Analysis Center (Auto-ISAC)

Standards and Policies Image

Automotive Open System Architecture (AUTOSAR)

Standards and Policies Image

Common Attack Pattern Enumeration and Classification (CAPEC)

Standards and Policies Image

Carnegie Mellon University Software Engineering Institute (SEI) Computer Emergency Response Team (CERT) Division

Standards and Policies Image

Center for Internet Security (CIS)

Standards and Policies Image

CIS Benchmarks

Standards and Policies Image

CIS Benchmarks Community

Standards and Policies Image

CIS WorkBench

Standards and Policies Image

Consortium for Information and Software Quality (CISQ)

Standards and Policies Image

Common Vulnerabilities and Exposures (CVE)

Standards and Policies Image

Common Weakness Enumeration (CWE)

Standards and Policies Image

Enterprise Singapore

Standards and Policies Image

International Electrotechnical Commission (IEC)

Standards and Policies Image

Institute of Electrical and Electronics Engineers (IEEE)

Standards and Policies Image

IEEE Technical Committee on Electric and Autonomous Vehicles (TC-EAV)

Standards and Policies Image

International Committee for Information Technology Standards (INCITS)

Standards and Policies Image

International Society of Automation (ISA)

Standards and Policies Image

International Standards Organization (ISO)

Standards and Policies Image

Information Technology Industry Council (ITI or ITI-C)

Standards and Policies Image

International Telecommunication Union (ITU) Telecommunication Standardization Sector (ITU-T)

Standards and Policies Image

Japan Automotive Software Platform and Architecture (JASPAR)

Standards and Policies Image

Japan Network Security Association (JNSA)

Standards and Policies Image

Ministry of Economy, Trade, and Industry (METI)

Standards and Policies Image

Motor Industry Software Reliability Association (MISRA)

Standards and Policies Image

National Institute of Standards and Technology (NIST)

Standards and Policies Image

National Telecommunications and Information Administration (NTIA)

Standards and Policies Image

Organization for the Advancement of Structured Information Standards (OASIS) Open and SARIF

Standards and Policies Image

Object Management Group (OMG)

Standards and Policies Image

SAE International

Standards and Policies Image

Singapore Standards Council

Standards and Policies Image

Standards Development Organisation

Standards and Policies Image

UL (formerly Underwriters Laboratories)