What is Software Assurance (SwA) and what are its two key properties?
Software Assurance is the level of confidence that software is free of vulnerabilities and behaves as intended — its two pillars are Trustworthiness and Predictable Execution.
* The two pillars as independent axes — three of the four quadrants are assurance failures. *
Software Assurance (SwA) is the level of confidence that software is free from vulnerabilities — whether intentionally designed in (a backdoor) or accidentally inserted at any point in its lifecycle — and that it functions in the intended manner. That wording is the long-standing US federal definition, quoted from the National Information Assurance Glossary (CNSS Instruction No. 4009); NIST's current glossary carries the same sentence under NISTIR 8074 Vol. 2.
Notice that assurance is a confidence level, not a binary state: you never "have" assurance, you have as much of it as your evidence — reviews, tests, provenance of dependencies — actually supports.
The two properties are deliberately split because they fail in different ways:
- Trustworthiness: no weaknesses an attacker (or an accident) can exploit. This is the security half — it is about the absence of bad behaviour.
- Predictable Execution: when you run it, it does exactly what it is supposed to. This is the correctness half — it is about the presence of good behaviour.
Tip: Trustworthy-but-unpredictable (secure yet buggy) and predictable-but-untrustworthy (works perfectly but has a backdoor) are both assurance failures — you need both halves, and testing only ever gives you strong evidence for the second one.
Go deeper:
Software assurance — NIST CSRC glossary — the federal definitions side by side, each with its source document.
Software assurance (Wikipedia) — how that confidence is actually accumulated in practice.