SAFECode outlines path to complete code integrity



Email    print   
June 28, 2010 —  (Page 1 of 2)
Automation, authentication and research are only pieces of the “reduction of vulnerability” pie. A team mentality and cohesion across the software supply chain play a big part as well, according to a report released June 14 by non-profit organization Software Assurance Forum for Excellence in Code (SAFECode).

The report, “An Overview of Software Integrity Controls: An Assurance-Based Approach to Minimizing Risks in the Software Supply Chain,” discusses different approaches organizations can take to ensure complete software integrity, such as contractual, technical and authenticity controls.

Bola Rotibi, research director at Creative Intellectual Consulting, pointed out: “The most important thing is not a tool or a technological approach, although these things are vital. It’s really more about an attitude, awareness and recognition [of a vulnerability] approach that should be applied before best practices.”

SAFECode’s members (Adobe, EMC, Juniper, Microsoft, Nokia, SAP and Symantec) naturally agreed with the paper’s premise, saying, “Focusing on the place where software is developed is less useful for improving security than focusing on the process by which software is developed and tested.” Focusing on the process helps ensure vendors, suppliers and employees alike are all on the same page, the report said.

Despite plenty of ways to assess and mitigate vulnerabilities, Rotibi said that, at the end of the day, there needs to be a concerted effort to look at where vulnerabilities will happen, to have the skills to recognize them, and the humility to admit a failure if a vulnerability does happen. Afterwards, that information also needs to be documented and passed along to ensure the vulnerability will be less likely to happen again, she added.
 
Other approaches, such as automating certain processes and reducing the amount of actual people touching the code, can certainly minimize risks, but this approach is not always entirely feasible either, said Michael Coté, an industry analyst with RedMonk. “If you buy into the trend of a lot more systems development going on,” which typically requires more people touching the code, then that kind of approach would be too difficult and time consuming to implement, he added.



Related Search Term(s): SAFECode

Pages 1 2 


Share this link: http://sdt.bz/34445
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
SAFECode guide advises developers on secure practices
The new guide offers such development tips as using fuzz testing, penetration testing and automated tools. The guide was composed from practices used by companies in the SAFECode organization Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb