Black Duck DevSecOps tools and services can help organizations comply with laws, regulatory guidance, policies, and standards related to application security (AppSec), software quality, data protection, and privacy. Avoid exploits by finding and fixing weaknesses and vulnerabilities using DevSecOps tools that provide detailed reports listing the specific rules and categories of each standard that the tools address.
To help raise the bar for software security and stay informed about the latest security issues, Black Duck employees serve or have served as subject matter experts for the committees, boards, working groups, programs, and projects related to AppSec standards, policies, and regulatory guidelines.
Automotive Industry Action Group (AIAG)
Carnegie Mellon University Software Engineering Institute (SEI) Computer Emergency Response Team (CERT) Division
CIS WorkBench
Enterprise Singapore
International Committee for Information Technology Standards (INCITS)
International Telecommunication Union (ITU) Telecommunication Standardization Sector (ITU-T)
Motor Industry Software Reliability Association (MISRA)
Object Management Group (OMG)
UL (formerly Underwriters Laboratories)
Automotive Information Sharing and Analysis Center (Auto-ISAC)
Center for Internet Security (CIS)
Consortium for Information and Software Quality (CISQ)
International Electrotechnical Commission (IEC)
International Society of Automation (ISA)
Japan Automotive Software Platform and Architecture (JASPAR)
National Institute of Standards and Technology (NIST)
SAE International
Automotive Open System Architecture (AUTOSAR)
CIS Benchmarks
Common Vulnerabilities and Exposures (CVE)
Institute of Electrical and Electronics Engineers (IEEE)
International Standards Organization (ISO)
Japan Network Security Association (JNSA)
National Telecommunications and Information Administration (NTIA)
Singapore Standards Council
Common Attack Pattern Enumeration and Classification (CAPEC)
CIS Benchmarks Community
Common Weakness Enumeration (CWE)
IEEE Technical Committee on Electric and Autonomous Vehicles (TC-EAV)
Information Technology Industry Council (ITI or ITI-C)
Ministry of Economy, Trade, and Industry (METI)
Organization for the Advancement of Structured Information Standards (OASIS) Open and SARIF
Standards Development Organisation