From the Editors: Opening up about security



Email    print   
August 15, 2010 —  (Page 1 of 2)
We are pleased that members of the Software Assurance Forum for Excellence in Code were active participants at the Black Hat Technical Security Conference and have begun to work together to devise new security best practices.

SAFECode members, including giants Adobe and Microsoft, took time to listen to the security community during a brainstorming session about how to produce more secure software over the next decade. Those ideas will be incorporated into white papers and best practices documents.

Not too long ago, most software makers would refuse to admit the presence of security vulnerabilities in their products. Secrecy didn’t make us more secure. We’re glad to see that more companies are talking about real-world security as well as sharing the details.

It is even more encouraging that SAFECode members are willing to learn from one another. Many of these software companies sell products that work with each other's respective products. Cooperation is necessary if end users' safety is to be sufficiently protected. Hackers collaborate. We need to do the same.

The more software makers take a full life-cycle approach to security, the better for all of us. Vulnerabilities can propagate down or up the stack, and security is only as strong as the weakest link, whether it’s in operating systems, off-the-shelf applications or custom code.

We hope that SAFECode's technical committees have learned from the Black Hat experience, and that those suggestions are put to good use.

Develop your master plan
Organizations looking to move to agile development practices—specifically Scrum—are encouraged to bring in trainers, or ScrumMasters, to get them started. This is the shared opinion of the experts interviewed for our special report on Scrum that begins on page 23 of this issue.

But did you know that students need only take a single two-day course, and pay a relatively small fee, to earn the Certified ScrumMaster label?

We understand that the concepts of Scrum are not difficult to grasp and the terminology is not overly confusing. But can anyone really become a master of anything in just a couple of days? We don’t believe so, especially not when organizations depend on those newly minted ScrumMasters to guide their agile practices.



Related Search Term(s): Scrum, security

Pages 1 2 


Share this link: http://sdt.bz/34557
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
Cigital Develops Ready-to-Use Tools for Securing the Smart Grid
Cigital Inc. announced the release of the Guide to Developing a Cyber Security and Risk Mitigation Plan Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb