The cybersecurity industry has developed over the last 20 years with a focus on fast attack detection and the availability of quick patches. However, Dell VP of Product and Application Security Eric Baize thinks the industry should shift its focus to get to the root of the problem – the software itself.

“Why don't we look a little bit at the root cause of the problem, which is the software we create," he said. “We want to eliminate vulnerabilities in software, but how do we do a better job of catching them early in the lifecycle?”

Cybersecurity is a complex problem, and when looking at all aspects that can create potential risk, Baize said software is clearly a major consideration. “On the other side of the zero day, you have a software development team that created software,” he added. 

“If software development teams caught bugs at the time they were creating the software, there wouldn't be a zero day to worry about on the other side," he said, adding that this is where building a secure development lifecycle (SDL) comes in.

The Secure Development Lifecycle

Baize said the idea of a SDL is to establish that developers are just as responsible for vulnerabilities as they are for bugs found in their software.

With this principle in mind, he added that careful thought must be taken at every step of the way when designing, developing, testing, and releasing software.

“It goes back to training the developer, by the way, because knowledge is key,” Baize said. A necessary part of training for software developers, he added, is to teach them to think like attackers. 

The way the Dell team approaches this is with a system Baize compared to belt ranks in martial arts. He said there is a base level of training, like the yellow belt, that is mandatory for every member on a development team. Dell’s Security Champion program also ensures that there is a “security champion” — someone who reaches a high level of training — on each team. 

It Starts With Education

In order to have a degree in software, training in security should be a requirement, Baize said.  

“If you're a construction engineer and you build a bridge or you build a high rise building, you want to make sure the construction engineer is trained on fire safety,” he added. “But we don't do the same on software.”

Baize foresees the next “battlefront” will be holding universities and other institutions accountable for training engineers. If they don’t, he said, it falls on companies to provide that training. While Dell has the resources to train developers, startups that are below what he calls the “security poverty line” do not.

“You don't have the budget, you're not training your software engineers,” he said. “So what you are creating is more security vulnerability, more issues that will continue to be around for years to come.”

Software Security Is a Process

One best practice Baize recommends to companies of any size is to keep a software bill of materials (SBOM), which can help manage code made up of components from many different places, like open source.

“That's common sense, and that's a very well-established best practice that any mature vendor will have,” he said. Although, he added there are 30 to 40 best practices for a SDL, and none of them alone can achieve the entire process. 

Because there is no silver bullet to solve security, Baize said evangelization is essential. Keeping discussion going amongst members of the industry and organizations like the Open Source Security Foundation are also key.  

“The more we discuss the concept of secure software development as a process, the more we will improve the security of society,” he said. “I like to say it's like being healthy. It takes a lot, and you cannot judge a vendor because they have a vulnerability. Because as much as you do everything right to be healthy, you may catch a flu.”