Issue No. 05 - September/October (2005 vol. 3)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2005.118
Kenneth R. van Wyk , Cigital and KRVW Associates
Gary McGraw , Cigital
Traditionally, software development efforts in large corporations have been about as far removed from information security as they were from human resources or any other business function. The disconnect between security and development has ultimately produced software development efforts that lack any sort of contemporary understanding of technical security risks. Today's complex and highly connected computing environments trigger myriad security concerns, so by blowing off the idea of security entirely, software builders virtually guarantee that their creations will have way too many security weaknesses that could--and should--have been avoided. This article presents some recommendations for solving this problem.
building security in, BSI, infosec, softdev
K. R. van Wyk and G. McGraw, "Bridging the Gap between Software Development and Information Security," in IEEE Security & Privacy, vol. 3, no. , pp. 75-79, 2005.