Secure Development Policy
Kwanso LLC
01 Jan 2022
To ensure that information security is designed and implemented within the development lifecycle for applications and information systems.
All Kwanso applications and information systems that are business critical and/or process, store, or transmit Confidential data. This policy applies to all internal and external engineers and developers of Kwanso software and infrastructure.
This policy describes the rules for the acquisition and development of software and systems that shall be applied to developments within the Kwanso organization.
Changes to systems within the development lifecycle shall be controlled by the use of formal change control procedures.
Significant code changes must be reviewed and approved by a developer or manager within the Reviewers before being merged into any production branch
All Kwanso software is version controlled and synced between contributors (developers). Access to the central repository is restricted based on an employee’s role. All code is written, tested, and saved in a local repository before being synced to the origin repository.
When operating platforms are changed, business critical applications shall be reviewed and tested to ensure that there is no adverse impact on organizational operations or security.
Modifications to third-party business application packages shall be discouraged, limited to necessary changes and all changes shall be strictly controlled.
Principles for engineering secure systems shall be established, documented, maintained and applied to any information system implementation efforts.
Software developers are expected to adhere to Kwanso’s coding standards throughout the development cycle, including standards for quality, commenting, and security.
Kwanso shall establish and appropriately protect secure development environments for system development and integration efforts that cover the entire system development life cycle.
Kwanso shall supervise and monitor the activity of outsourced system development. Outsourced development shall adhere to all Kwanso standards and policies.
Testing of security functionality shall be carried out during development. No code shall be deployed to Kwanso production systems without documented, successful test results.
Acceptance testing programs and related criteria shall be established for new information systems, upgrades and new versions.
Prior to deploying code, a Release Checklist MUST be completed which includes a checklist of all Test Plans which show the completion of all associated tests.
Test data shall be selected carefully, protected and controlled. Confidential customer data shall be protected in accordance with all contracts and commitments. Customer data shall not be used for testing purposes without the explicit permission of the data owner and the Engineering Manager.
The acquisition of third-party systems and software shall be done in accordance with the requirements of the Kwanso Third-Party Management Policy.
Requests for an exception to this Policy must be submitted to the Engineering Manager for approval.
Any known violations of this policy should be reported to the Engineering Manager. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.