Standards provide the basis for demonstrating compliance with laws, policies, and regulatory guidelines.
Black Duck DevSecOps tools and services can help organizations comply with laws, regulatory guidance, policies, and standards related to application security (AppSec), software quality, data protection, and privacy. Avoid exploits by finding and fixing weaknesses and vulnerabilities using DevSecOps tools that provide detailed reports listing the specific rules and categories of each standard that the tools address.
To help raise the bar for software security and stay informed about the latest security issues, Black Duck employees serve or have served as subject matter experts for the committees, boards, working groups, programs, and projects related to AppSec standards, policies, and regulatory guidelines.
Automotive Industry Action Group (AIAG)
Automotive Information Sharing and Analysis Center (Auto-ISAC)
Automotive Open System Architecture (AUTOSAR)
Common Attack Pattern Enumeration and Classification (CAPEC)
Carnegie Mellon University Software Engineering Institute (SEI) Computer Emergency Response Team (CERT) Division
Center for Internet Security (CIS)
CIS Benchmarks
CIS Benchmarks Community
CIS WorkBench
Consortium for Information and Software Quality (CISQ)
Common Vulnerabilities and Exposures (CVE)
Common Weakness Enumeration (CWE)
Enterprise Singapore
International Electrotechnical Commission (IEC)
Institute of Electrical and Electronics Engineers (IEEE)
IEEE Technical Committee on Electric and Autonomous Vehicles (TC-EAV)
International Committee for Information Technology Standards (INCITS)
International Society of Automation (ISA)
International Standards Organization (ISO)
Information Technology Industry Council (ITI or ITI-C)
International Telecommunication Union (ITU) Telecommunication Standardization Sector (ITU-T)
Japan Automotive Software Platform and Architecture (JASPAR)
Japan Network Security Association (JNSA)
Ministry of Economy, Trade, and Industry (METI)
Motor Industry Software Reliability Association (MISRA)
National Institute of Standards and Technology (NIST)
National Telecommunications and Information Administration (NTIA)
Organization for the Advancement of Structured Information Standards (OASIS) Open and SARIF
Object Management Group (OMG)
SAE International
Singapore Standards Council
Standards Development Organisation