CyberMed

Tools and Resources

Secure Development & Testing · 1 min read

Development Tools

  • SAST: SonarQube, Coverity, Fortify
  • DAST: OWASP ZAP, Burp Suite
  • Fuzzing: AFL++, Peach, LibFuzzer
  • SBOM: SPDX tools, CycloneDX

Standards and Guidelines

  • OWASP: Application Security Verification Standard
  • CERT: Secure Coding Standards
  • NIST: Secure Software Development Framework
  • IEC 62304: Medical device software lifecycle

Training Resources

  • SANS Secure Coding courses
  • OWASP Training materials
  • ISC2 CSSLP certification
  • Medical device specific training

Sources

Primary documents named in this section:

  1. NIST SP 800-218, Secure Software Development Framework (SSDF), NIST.
  2. CycloneDX Bill of Materials Specification, OWASP Foundation.
  3. SPDX: System Package Data Exchange, The Linux Foundation.
  4. IEC 62304:2006 (with Amd 1:2015), Medical device software: Software life cycle processes, IEC.

See how your device measures up

Take the free FDA 524B readiness assessment and get a personalized gap report covering this topic and more.

Check Your Readiness

Need the documents written, not just checked? CyberMed writes the eSTAR cybersecurity section and runs the penetration testing behind it.