May 26, 2005

Adopting a Software Security Improvement Program

Dan Taylor and Gary McGraw from Cigital have written an interesting article for IEEE Security & Privacy about "Adopting a Software Security Improvement Program". In it, the authors go into software security best practices and show how a well-defined roadmap lays out the specifics of how best to deploy software security best practices given a particular organization’s approach to building software.

I like how they broke this down into six key phases:

  1. Stop the Bleeding
  2. Harvest the low hanging fruit
  3. Establish a foundation
  4. Craft core competencies
  5. Develop differentiators
  6. Build out the "nice to haves"

Sound interesting? You will have to go read the article to find out what those phases REALLY mean. You can check out the article here.

Posted by SilverStr at May 26, 2005 12:30 PM | TrackBack