Access "Secure coding essential to risk mitigation planning"
This article is part of the January 2004 issue of IDSes takes aim: Emerging "target-based" systems improve intrusion defense
"The root of the vulnerability problem is that programmers don't know how to code securely. If programmers were taught security in the first place, my job would be 100 times easier." How many times have you heard this? All together now, repeat after me: Not gonna happen. Don't get me wrong. Building secure software is a laudable goal. It boosts productivity and reduces costs. According to one study, it's 6.5 times more expensive to fix a security problem in the implementation phase than in the design phase of a software rollout. By the time you get to the maintenance phase, it's 100 times more expensive. But we'll burn too much time and energy chasing a totally impractical objective. Secure programming is an oxymoron because none of the parties who could make it happen on a broad scale are properly "incentivized." Industry leaders care about two things: how to make more money and how to spend less. The notion that secure programming helps them increase efficiency and cut costs in the long run ignores the fact that it's faster and cheaper to build crappy ... Access >>>
Access TechTarget
Premium Content for Free.
What's Inside
Features
-
-
'Targeted' perimeter defense improves network-based intrusion detection systems
by Joel Snyder
Target-based IDSes squelch network noise to pinpoint the alerts you really care about. We review three solutions to see if they hit the bull's-eye.
-
Microsoft Trustworthy Computing causes strategic conflict around security
by Lawrence M. Walsh
Two years into Trustworthy Computing, the software giant faces the daunting challenge of winning and keeping customers while grappling with periodic setbacks.
-
Ron Rivest, RSA Algorithm Creator, discusses issues with micropayments
by Andrew Briney
Legendary cryptographer Ron Rivest has a reputation for tackling "hard" security problems. Up next: Micropayments.
-
'Targeted' perimeter defense improves network-based intrusion detection systems
by Joel Snyder
-
-
Passive scanning: A new take on network vulnerability scanning
by Joel Snyder
Learn about the benefits and risks of passive network vulnerability scanning.
-
Business continuity roles improve security incident management
by Fred Trickey
IT personnel may be front-line responders, but if they "own" incident management, your enterprise is at risk. Here's a business blueprint for an effective security incident management program with business continuity roles.
-
Review: RSA ClearTrust 5.5 secure federated identity management system
by George Wrenn
RSA ClearTrust 5.5 eases the administration of securing Web services identity management across business partners' systems.
-
Passive scanning: A new take on network vulnerability scanning
by Joel Snyder
-
Columns
-
Secure coding essential to risk mitigation planning
by Andrew Briney, Information Security magazine
Information Security magazine's editorial director Andrew Briney talks about the lack of incentive for making code more secure.
-
Examining hacker bounty pros and cons: Do they stop computer hackers?
A hacker bounty could create a new benchmark for hackers to measure themselves, so do bounties stop computer hackers?
-
Understanding the Open Systems Interconnection model
by Jay Heiser, Contributor
It's time to take the Open Systems Interconnection (OSI) model up a notch to the human layer.
-
Spammers drive organizations to block Internet traffic to stop attacks
by Dana W. Paxson
Spammers and hackers are driving organizations -- and nations -- to block Internet traffic in order to stop attacks.
-
Secure coding essential to risk mitigation planning
by Andrew Briney, Information Security magazine
More Premium Content Accessible For Free
Next-generation firewalls play by new rules
E-Zine
Firewalls started their journey to the next generation at about the same time as the Star Trek TV series. While the products have advanced with ...
Developing your endpoint security management transition plan
E-Handbook
This TechGuide will help you develop your endpoint security management transition plan. Articles focus on overcoming the challenges of Web-based ...
Unlock new pathways to network security architecture
E-Zine
Network security architecture is showing its age at many organizations. With new technology, different data types, and use of multi-generations of ...
Security Management Strategies for the CIO