All About Web Application Security Programmes
Today I thought I'd share some of my favourite blog posts about building software securely by implementing web application security programmes.
The excellent blog posts about building a software security assurance programme are:
- Rafal Los on Enterprise Web Application Security and Building a Web Application Security Program Without a Budget
- Justin Clarke on The Fallacy of Secure Software
- Adrian Lane on Agile Development and Security
Can you recommend any others?
As a reminder, the main software security maturity models and process models are:
- Building Security In Maturity Model (BSIMM)
- Microsoft Security Development Lifecycle (SDL)
- National Institute of Standards and Technology (NIST) SP 800-64 Rev2 Security Considerations in the Information System Development Life Cycle
- Software Assurance Maturity Model (SAMM)
Last week Microsoft also released a short document describing how to implement a simplified version of their SDL.
Which should you choose? It's what works in your own organisation that matters. Ask your software suppliers (e.g. web developers) what they use before you buy.
Posted on: 09 February 2010 at 17:36 hrs

Comments are filtered automatically and should appear shortly after they been checked.