software security assurance
process that helps design and implement software that protects the data and resources involved in that software
STRIDE
Process for modelling software security threats, standing for Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege