<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SEI Blog | Secure Development</title><link>http://www.sei.cmu.edu/feeds/topic/</link><description>Updates on changes and additions to the                         SEI Blog for posts matching Secure Development</description><atom:link href="http://www.sei.cmu.edu/blog/feeds/topic/secure-development/rss/" rel="self"/><language>en-us</language><lastBuildDate>Wed, 04 Mar 2026 00:00:00 -0500</lastBuildDate><item><title>The Five Pillars of Software Assurance in System Acquisition</title><link>https://www.sei.cmu.edu/blog/the-five-pillars-of-software-assurance-in-system-acquisition/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post presents five foundational capabilities to support the acquisition of a system with effective software assurance.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dr. Carol Woody, Christopher Alberts, Michael Bandor, Timothy A. Chick</dc:creator><pubDate>Wed, 04 Mar 2026 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/the-five-pillars-of-software-assurance-in-system-acquisition/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Tailoring 9 Zero Trust and Security Principles to Weapon Systems</title><link>https://www.sei.cmu.edu/blog/tailoring-9-zero-trust-and-security-principles-to-weapon-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Our latest post outlines how 9 zero trust and security principles might apply to weapon systems.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christopher Alberts, Timothy Morrow, Rhonda Brown, Charles Wallen</dc:creator><pubDate>Tue, 09 Dec 2025 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/tailoring-9-zero-trust-and-security-principles-to-weapon-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>AI-Powered Memory Safety with the Pointer Ownership Model</title><link>https://www.sei.cmu.edu/blog/ai-powered-memory-safety-with-the-pointer-ownership-model/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post highlights work to automate C Code Security with AI-Powered memory safety.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda, Lori Flynn</dc:creator><pubDate>Wed, 03 Dec 2025 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/ai-powered-memory-safety-with-the-pointer-ownership-model/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Managing Security and Resilience Risks Across the  Lifecycle</title><link>https://www.sei.cmu.edu/blog/managing-security-and-resilience-risks-across-the-lifecycle/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post introduces the Security Engineering Framework, a schema of software-focused engineering practices that acquisition programs can use to manage security and resilience risks across the lifecycle.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christopher Alberts, Charles Wallen, Dr. Carol Woody, Michael Bandor</dc:creator><pubDate>Wed, 23 Jul 2025 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/managing-security-and-resilience-risks-across-the-lifecycle/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Detection and Repair: The Cost of Remediation</title><link>https://www.sei.cmu.edu/blog/detection-and-repair-the-cost-of-remediation/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This year, we plan on making some exciting updates to the SEI CERT C Coding Standard. This blog post is about one of our ideas for improving the standard.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 03 Mar 2025 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/detection-and-repair-the-cost-of-remediation/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Measurement Challenges in  Software Assurance and Supply Chain Risk Management</title><link>https://www.sei.cmu.edu/blog/measurement-challenges-in-software-assurance-and-supply-chain-risk-management/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This SEI Blog post examines the current state of measurement in software assurance and supply chain management, with a particular focus on open source software, and highlights promising measurement approaches.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nancy Mead, Dr. Carol Woody, Scott Hissam</dc:creator><pubDate>Mon, 20 May 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/measurement-challenges-in-software-assurance-and-supply-chain-risk-management/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Supply Chain Assurance</category></item><item><title>What Recent Vulnerabilities Mean to Rust</title><link>https://www.sei.cmu.edu/blog/what-recent-vulnerabilities-mean-to-rust/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>In recent weeks several vulnerabilities have rocked the Rust community causing many to question its safety. This post examines two such vulnerabilities.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 29 Apr 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/what-recent-vulnerabilities-mean-to-rust/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Rust</category></item><item><title>The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain</title><link>https://www.sei.cmu.edu/blog/the-sei-sbom-framework-informing-third-party-software-management-in-your-supply-chain/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post presents a framework to promote the use of SBOMs and establish practices and processes that organizations can leverage as they build their programs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christopher Alberts, Michael Bandor, Charles Wallen, Dr. Carol Woody</dc:creator><pubDate>Mon, 06 Nov 2023 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/the-sei-sbom-framework-informing-third-party-software-management-in-your-supply-chain/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Supply Chain Assurance</category><category>Acquisition Transformation</category></item><item><title>Rust Vulnerability Analysis and Maturity Challenges</title><link>https://www.sei.cmu.edu/blog/rust-vulnerability-analysis-and-maturity-challenges/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post explores tools for understanding vulnerabilities in the Rust programming language as well as the maturity of the Rust software ecosystem as a whole and how that might impact future security responses.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Garret Wassermann, David Svoboda</dc:creator><pubDate>Mon, 23 Jan 2023 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/rust-vulnerability-analysis-and-maturity-challenges/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Rust</category></item><item><title>Rust Software Security: A Current State Assessment</title><link>https://www.sei.cmu.edu/blog/rust-software-security-a-current-state-assessment/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post examines security issues with the Rust programming language.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joe Sible, David Svoboda</dc:creator><pubDate>Mon, 12 Dec 2022 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/rust-software-security-a-current-state-assessment/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Rust</category></item><item><title>Taking Up the Challenge of Open Source Software Security in the DoD</title><link>https://www.sei.cmu.edu/blog/taking-up-the-challenge-of-open-source-software-security-in-the-dod/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post describes a workshop hosted by the SEI to start a conversation to elevate the trustworthiness of free and open source software, particularly in DoD settings.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Hissam</dc:creator><pubDate>Mon, 15 Aug 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/taking-up-the-challenge-of-open-source-software-security-in-the-dod/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Software Assurance</category><category>Supply Chains</category></item><item><title>11 Leading Practices When Implementing a Container Strategy</title><link>https://www.sei.cmu.edu/blog/11-leading-practices-when-implementing-a-container-strategy/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>While containers are frequently lauded in the latest software development trends, switching from using virtual machines and deploying an organization-wide container strategy remains non-trivial.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Mellinger, William Nichols, Jay Palat</dc:creator><pubDate>Mon, 08 Nov 2021 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/11-leading-practices-when-implementing-a-container-strategy/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Release of SCAIFE System Version 2.0.0 Provides Support for Continuous-Integration (CI) Systems</title><link>https://www.sei.cmu.edu/blog/release-of-scaife-system-version-200-provides-support-for-continuous-integration-ci-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Key features in new release of SCAIFE System Version 2.0.0 including support for continuous-integration (CI) systems, and status of evolving SEI SCAIFE work</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lori Flynn</dc:creator><pubDate>Mon, 25 Oct 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/release-of-scaife-system-version-200-provides-support-for-continuous-integration-ci-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Continuous Deployment of Capability</category><category>SCALE: A Static Analysis Auditing Tool</category><category>Secure Coding</category><category>Machine Learning</category><category>Static Analysis</category><category>Static Analysis Classification and Prioritization</category><category>Secure Development</category><category>Artificial Intelligence</category><category>Source Code Analysis Integrated Framework Environment (SCAIFE)</category></item><item><title>A Technique for Decompiling Binary Code for Software Assurance and Localized Repair</title><link>https://www.sei.cmu.edu/blog/a-technique-for-decompiling-binary-code-for-software-assurance-and-localized-repair/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The DoD has a significant amount of software available only in binary form. It is impractical to ensure that this software is free from vulnerabilities and malicious code.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Klieber</dc:creator><pubDate>Mon, 11 Oct 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/a-technique-for-decompiling-binary-code-for-software-assurance-and-localized-repair/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Anti-Tamper for Software Components</title><link>https://www.sei.cmu.edu/blog/anti-tamper-for-software-components/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post explains how to identify software components within systems that are in danger of being exploited and that should be protected by anti-tamper practices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Hissam</dc:creator><pubDate>Mon, 21 Jun 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/anti-tamper-for-software-components/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Software Assurance</category><category>System Resilience</category><category>Cyber Risk and Resilience Management</category><category>Supply Chains</category></item><item><title>A Public Repository of Data for Static-Analysis Classification Research</title><link>https://www.sei.cmu.edu/blog/public-repository-data-static-analysis-classification-research/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post describes a new repository of labeled data that CERT is making publicly available for many code-flaw conditions. Researchers can use this dataset along with the associated code and tool output to monitor and test the performance of their automated classification of meta-alerts.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lori Flynn</dc:creator><pubDate>Mon, 02 Nov 2020 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/public-repository-data-static-analysis-classification-research/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Static Analysis Classification and Prioritization</category><category>SCALE: A Static Analysis Auditing Tool</category><category>Source Code Analysis Integrated Framework Environment (SCAIFE)</category></item><item><title>Automated Code Repair to Ensure Memory Safety</title><link>https://www.sei.cmu.edu/blog/automated-code-repair-to-ensure-memory-safety/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Memory-safety vulnerabilities are among the most common and most severe types of software vulnerabilities. In early 2019, a memory vulnerability in the iPhone iOS....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Klieber</dc:creator><pubDate>Mon, 24 Feb 2020 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/automated-code-repair-to-ensure-memory-safety/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Secure Coding</category><category>Secure Development</category></item><item><title>An Application Programming Interface for Classifying and Prioritizing Static Analysis Alerts</title><link>https://www.sei.cmu.edu/blog/an-application-programming-interface-for-classifying-and-prioritizing-static-analysis-alerts/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>In this post, we describe the Source Code Analysis Integrated Framework Environment (SCAIFE) application programming interface (API). SCAIFE is an architecture for classifying and prioritizing static analysis alerts.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lori Flynn, Ebonie McNeil</dc:creator><pubDate>Mon, 22 Jul 2019 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/an-application-programming-interface-for-classifying-and-prioritizing-static-analysis-alerts/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Static Analysis Classification and Prioritization</category><category>SCALE: A Static Analysis Auditing Tool</category></item><item><title>How to Use Static Analysis to Enforce SEI CERT Coding Standards for IoT Applications</title><link>https://www.sei.cmu.edu/blog/how-to-use-static-analysis-to-enforce-sei-cert-coding-standards-for-iot-applications/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The Jeep hack, methods to hack ATMs, and even hacks to a casino's fish tank provide stark evidence of the risks associated with the Internet of Things (IoT)....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 01 Apr 2019 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/how-to-use-static-analysis-to-enforce-sei-cert-coding-standards-for-iot-applications/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Security-Related Requirements</category><category>Secure Coding</category><category>Cyber Risk and Resilience Management</category><category>Static Analysis</category><category>Cybersecurity</category><category>Secure Development</category><category>Cyber Missions</category><category>Best Practices in Network Security</category></item><item><title>Using the SEI CERT Coding Standards to Improve Security of the Internet of Things</title><link>https://www.sei.cmu.edu/blog/using-the-sei-cert-coding-standards-to-improve-security-of-the-internet-of-things/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The Internet of Things (IoT) is insecure. The Jeep hack received a lot of publicity, and there are various ways to hack ATMs, with incidents occurring with increasing regularity....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 11 Feb 2019 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/using-the-sei-cert-coding-standards-to-improve-security-of-the-internet-of-things/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Security-Related Requirements</category><category>Secure Coding</category><category>Secure Development</category><category>Cyber Missions</category><category>Internet of Things</category></item></channel></rss>