Issue No.05 - September/October (2005 vol.3)
Kenneth R. van Wyk , Cigital and KRVW Associates
Gary McGraw , Cigital
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2005.118
Traditionally, software development efforts in large corporations have been about as far removed from information security as they were from human resources or any other business function. The disconnect between security and development has ultimately produced software development efforts that lack any sort of contemporary understanding of technical security risks. Today's complex and highly connected computing environments trigger myriad security concerns, so by blowing off the idea of security entirely, software builders virtually guarantee that their creations will have way too many security weaknesses that could--and should--have been avoided. This article presents some recommendations for solving this problem.
building security in, BSI, infosec, softdev
Kenneth R. van Wyk, Gary McGraw, "Bridging the Gap between Software Development and Information Security", IEEE Security & Privacy, vol.3, no. 5, pp. 75-79, September/October 2005, doi:10.1109/MSP.2005.118