Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 1 March 2010

SANS Institute recommends for more code development practices

Posted on 09:11 by Unknown

Fortify gives thumbs up to SANS Institute-led request for more secure code development practices

Reports that a group of organisations, led by the SANS Institute and Mitre Group, are calling for corporate customers to request more secure code development practices from their software suppliers have been applauded by Fortify Software.

The software security specialists says that Tuesday's announcement (http://bit.ly/dwO19P) by a consortium of more than 30 enterprise customers of software vendors is good news as it give companies the draft text for use in their procurement contracts with vendors.

"Best practice in code development has been under active discussion by the software vendor community for some time, but it's good to hear that the SANS Institute has grasped the bull by the horns, and done something practical about the issue," said Richard Kirk, Fortify's European director.

"Our own observations suggest that a large number of successful hacker attacks are caused, in part, by software flaws, which give the hackers a small chink in an application's armour to prise open," he added.

According to Kirk, by encouraging companies to include suitable language in their procurement contracts, the consortium will hopefully drive the software development industry to adopt the best practices that a number of experts have been calling on for some time.

The Fortify director went on to say that, in his company's March 2009 report – 'Building in security in government software' (http://bit.ly/9f53Ge) – it recommended that the industry should adopt a best practice approach to software code development, building in security from the earliest point in an application's development and to conduct thorough security tests of software prior to acceptance.

The report, which was issued around the time of President's Obama's appointment of a federal chief technology officer, noted that the appointment - in the US at least - was an opportunity for government to adopt these best practices across the board.

It was interesting, said Kirk, to read that former White House security advisor Howard Schmidt - and president of the Information Security Forum - commenting that, despite its excellent goals, the US Federal Information Security Management Act (FISMA) has not managed to solve the software development industry's security problems (http://bit.ly/c0phgR).

"But, as Fortify's founder and chief scientist Brian Chess also said at the time, if FISMA has done nothing else, it has helped to identify the problem," he explained.

It's against this backdrop that Fortify is pleased to add its support to the SANS Institute-led call for more secure program code development, and the introduction of best practices in the application development industry.

"Changes of this type aren't going to happen overnight, as software vendors will have to engender new working practices in their code development operations," he said.

"However, if their clients start mandating the use of best practices in their commercial agreements - through the use of the correct language in procurement contracts - then that is something we can wholly support," he added.

For more on Fortify Software: http://www.fortify.com

Source: Eskenzi PR

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ▼  March (13)
      • New password-stealing virus targets Facebook
      • IT experts warn users turn off WiFi to prevent lap...
      • Personal data of 15,000 National Guardsmen lost
      • Industrialized cyber attacks infect educational se...
      • Imperva launch new service to block automated cybe...
      • Brocade welcomes Government’s IT Strategy
      • Mobile workforce shift will cause security headach...
      • Dell put Credant's Encryption on all Commercial cl...
      • ISACA Leader Says 2010 Will be Year of the Cloud
      • Web 2.0 services are the next security hurdle says...
      • MiFi and MC998D launch on Virgin Mobile Canada
      • It’s Better to Prevent than to Cure
      • SANS Institute recommends for more code developmen...
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile