DHS Unveils Security Scoring System for Software Flaws, Attack Vectors

June 28, 2011

The United States Department of Homeland Security unveiled a detailed guide to help software developers and vendors avoid common security errors in their applications.

Homeland Security’s Cyber-Security Division worked with the security training and research organization SANS Institute and the non-profit technology research company Mitre to create a list of common software vulnerabilities along with a scoring system to prioritize flaws, a risk analysis framework to evaluate the seriousness of the flaws and a list of top 25 dangerous software errors. The guide wasreleased June 27 and is intended to help organizations hold their developers and vendors accountable for problems in the application.

Link to the list