Tema: compliance
-
Registros de auditoría: qué registrar, cómo mantenerlos íntegros y quién puede leerlos
Un registro de auditoría responde a quién hizo qué a qué objeto, cuándo y con qué resultado; lo escribe la propia aplicación para cada acción relevante para la seguridad, se mantiene separado de los logs de depuración, se protege contra alteraciones trasladándolo con prontitud a un almacenamiento de solo anexado o de escritura única, y se lee solo bajo un acceso restringido y registrado.
-
Choosing an open-source licence
Permissive licences (MIT, Apache-2.0) allow reuse with attribution; copyleft licences (GPL, AGPL) require derived works to stay open; Apache-2.0 adds a patent grant. Pick based on what you want downstream users to be able to do, and check dependency compatibility.
-
Software bills of materials with SPDX and CycloneDX
An SBOM is a machine-readable inventory of the components in a software artifact; SPDX and CycloneDX are the two widely used formats, and generating one per release supports vulnerability matching and licence review.
-
Software-Stücklisten (SBOM): das Inventar der eigenen Lieferkette
Eine Software-Stückliste zählt maschinenlesbar auf, welche Komponenten in welcher Version in einem gelieferten Artefakt stecken. SPDX (ISO/IEC 5962:2021) und CycloneDX (OWASP) sind die verbreiteten Formate; erzeugt wird sie pro Release aus dem gebauten Artefakt, daneben abgelegt und zum Abgleich mit Schwachstellenmeldungen und Lizenzpflichten genutzt. Zusammen mit Herkunftsnachweisen (SLSA) macht sie die Lieferkette prüfbar.
Legible por máquina: JSON