Software Security Myth #5: It’s All About Finding Bugs In Your Code
Are bugs a big deal in the software security conversation? Absolutely. Implementation bugs in code account for at least half of the overall software security problem. Finding and fixing those bugs is...
View ArticleThe Tech Talent Challenge: Recruiting in Software Security
Recruiting for a leading software security consulting firm poses tech talent challenges that even top recruiters find overwhelming. How do you find a population of individuals who, by profession,...
View ArticleGetting Started With Architecture Analysis Or Secure Design Review
So you understand the difference between bugs and flaws and that the defect universe is roughly a 50/50 split of bugs and flaws. Awesome! (If you don’t yet understand the difference, here’s a great...
View Article4 Signs You Need a Proactive Application Security Approach
Organizations usually start paying attention to application security when they’re in a reactive mode. Once something happens involving their firm’s security stance, security becomes a high priority....
View ArticleAnnotated AT&T Cybersecurity Conference Keynote + Resources
As painful as it can be to watch yourself perform, I spent 45 minutes watching myself walk around a well-lit NYC stage delivering the keynote talk for this year’s AT&T Cybersecurity Conference....
View ArticleSoftware Security Myth #3: Penetration Testing Solves Everything
Security testing is important. Conducting specialized penetration tests at the end of the software development lifecycle (SDLC) can be a rewarding security activity for your organization. Penetration...
View ArticleBuilding Security In Maturity Model: 5 Lessons Learned from BSIMM6
By providing actual measurement data from the field, the Building Security In Maturity Model (BSIMM) makes it possible to build a long-term plan for a software security initiative (SSI) and track...
View ArticleThird-Party Security Risk Factors
As we build our budgets for 2016, many organizations are examining 2015 pitfalls in order to strategize where to spend money in the upcoming year. With the recent influx of security breaches, many are...
View ArticleSoftware Security Myth #2: A Tool Is All You Need For Software Security
All software projects produce at least one common artifact—code. This source code is the number one software security touchpoint your organization should address when strategizing a software security...
View ArticleCaching Security Architecture Knowledge with Design Patterns
Cigital has always done architecture work. In the past clients replaced their legacy systems with ‘new-fangled’ JavaEE. As they explored platform features, an ecosystem of web frameworks, and related...
View ArticleSoftware Security Myth #1: Perimeter Security Can Secure Your Applications
As you probably well know, new technologies are moving at incredible speeds these days. That’s why building secure software should be a top priority in your organization. As more software is created,...
View ArticleThe 3 Fundamentals of a Software Security Initiative
You take calculated risks every day. Just this morning, say you decided to walk across the street against the light because no cars were in sight and you had to get to work on time. But had that...
View ArticleGary McGraw Delivers AT&T Cybersecurity Conference Keynote
The 17th annual AT&T Cybersecurity Conference is taking place in New York City on October 5-6. During the two-day event, a security conversation will be taking place among industry leaders about...
View ArticleBenefits of Code Scanning for Code Review
“All software projects are guaranteed to have one artifact in common – source code. Because of this guarantee, it make sense to center a software assurance activity around code itself.” -Gary McGraw,...
View ArticleDevelopers Targeted in Apple’s iOS Malware Attack
Apple is currently taking measures to eradicate hundreds (potentially thousands) of malicious apps recently discovered in the iOS App Store. It has come to light that hackers distributed a modified...
View Article5 Ways to Pay Your Technical Debt Back
Benjamin Franklin once said there were only two things certain in life: death and taxes—unless you’re responsible for information security, of course. In that case, you can add a third, technical...
View ArticleSecureAssist Helps Developers Build Security Into Any Software Development...
The Issue The primary goal of a software developer is to get through the edit, compile, debug workflow as efficiently as possible, ensuring that software is working correctly and is delivered on time....
View ArticleSecurity Researchers Expose Bugs and Their Vendors
In the day and age where applications are constantly surveyed and found to have bugs, the communication behind reporting them has stirred much controversy, especially in eyes of security researchers....
View ArticleMcGraw Asks Who’s in Charge of Medical Device Security
In his latest SearchSecurity article, Gary McGraw discusses the risks behind medical devices that are deeper than patient data, including patient safety risk and in worst cases, death, which can result...
View ArticleGary McGraw discusses the security risks of dynamic code
Dynamic language and associated development and operations (DevOps) methodologies change and evolve constantly. Due to these intentionally ever-changing dynamic aspects of software, security measures...
View Article