<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Software Process on Learnable Secure SDLC</title><link>https://sdlc.learnable.team/process/</link><description>Recent content in Software Process on Learnable Secure SDLC</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://sdlc.learnable.team/process/index.xml" rel="self" type="application/rss+xml"/><item><title>Exception Register</title><link>https://sdlc.learnable.team/process/exception_register/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://sdlc.learnable.team/process/exception_register/</guid><description>Exception Register # Where a team cannot meet a control defined in this process, the deviation is recorded as an exception, along with the rationale for it. Recording an exception is always preferable to quietly diverging from the process.
The current list of exceptions is maintained in the team wiki, which is the authoritative record. Anyone with Learnable access can find it there.
No list and no link appear on this page.</description></item><item><title>Risk Register</title><link>https://sdlc.learnable.team/process/risk_register/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://sdlc.learnable.team/process/risk_register/</guid><description>Risk Register # The risk register is the list of risks this process exists to control, together with their severity, ownership, and current status.
It is maintained in Linear, which is the authoritative record. Anyone with Learnable access can find it there.
No list and no link appear on this page. This site is published publicly, whereas the register itself is internal. Each control described in this process carries a rationale explaining the risk it addresses, so the reasoning behind a control stays with the control itself.</description></item><item><title>Training</title><link>https://sdlc.learnable.team/process/training/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://sdlc.learnable.team/process/training/</guid><description>Training # The team will annually go through the OWASP top 10 security risks and discuss them. The date of the session and its participants will be recorded in a compliance system of record. For new employees the OWASP top 10 will be done together with one of the other team members.</description></item></channel></rss>