Issue No. 04 - July-Aug. (2011 vol. 9)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2011.88
John Diamant , Hewlett-Packard
The software industry would be better off with more emphasis on early-lifecycle security—avoiding security mistakes in the first place. That means security requirements analysis and architecting or designing security in, an approach that's rare but that provides substantial benefits.
software development, HP Comprehensive Applications Threat Analysis, W. Edwards Deming, security vulnerabilities, dynamic application security testing, static application security testing, security requirements gap analysis, architectural threat analysis, security quality, zero day, 0-day, security and privacy
J. Diamant, "Resilient Security Architecture: A Complementary Approach to Reducing Vulnerabilities," in IEEE Security & Privacy, vol. 9, no. , pp. 80-84, 2011.