2014CERN Document Server (European Organization for Nuclear Research)Requires access

Enterprise Software Security: A Confluence of Disciplines

Kenneth R. van Wyk, Mark G. Graff, Dan S. Peters, Diana Burley

Open publisher page 4 citations

Abstract

STRENGTHEN SOFTWARE SECURITY BY HELPING DEVELOPERS AND SECURITY EXPERTS WORK TOGETHER Traditional approaches to securing software are inadequate. The solution: Bring software engineering and network security teams together in a new, holistic approach to protecting the entire enterprise. Now, four highly respected security experts explain why this confluence is so crucial, and show how to implement it in your organization. Writing for all software and security practitioners and leaders, they show how software can play a vital, active role in protecting your organization. Youll learn how to construct software that actively safeguards sensitive data and business processes and contributes to intrusion detection/response in sophisticated new ways. The authors cover the entire development lifecycle, including project inception, design, implementation, testing, deployment, operation, and maintenance. They also provide a full chapter of advice specifically for Chief Information Security Officers and other enterprise security executives. Whatever your software security responsibilities, Enterprise Software Security delivers indispensable big-picture guidanceand specific, high-value recommendations you can apply right now. COVERAGE INCLUDES: Overcoming common obstacles to collaboration between developers and IT security professionals Helping programmers design, write, deploy, and operate more secure software Helping network security engineers use application output more effectively Organizing a software security team before youve even created requirements Avoiding the unmanageable complexity and inherent flaws of layered security Implementing positive software design practices and identifying security defects in existing designs Teaming to improve code reviews, clarify attack scenarios associated with vulnerable code, and validate positive compliance Moving beyond pentesting toward more comprehensive security testing Integrating your new application with your existing security infrastructure Ruggedizing DevOps by adding infosec to the relationship between development and operations Protecting application security during maintenance

About this research paper

What this paper is about

STRENGTHEN SOFTWARE SECURITY BY HELPING DEVELOPERS AND SECURITY EXPERTS WORK TOGETHER Traditional approaches to securing software are inadequate. The solution: Bring software engineering and network security teams together in a new, holistic approach to protecting the entire enterprise. Now, four highly respected security experts explain why this confluence is so crucial, and show how to implement it in your organization. Writing for all software and security practitioners and leaders, they show how software can play a vital, active role in protecting your organization. Youll learn how to construct software that actively safeguards sensitive data and business processes and contributes to intrusion detection/response in sophisticated new ways. The authors cover the entire development lifecycle, including project inception, design, implementation, testing, deployment, operation, and maintenance. They also provide a full chapter of advice specifically for Chief Information Security Officers and other enterprise security executives. Whatever your software security responsibilities, Enterprise Software Security delivers indispensable big-picture guidanceand specific, high-value recommendations you can apply right now. COVERAGE INCLUDES: Overcoming common obstacles to collaboration between developers and IT security professionals Helping programmers design, write, deploy, and operate more secure software Helping network security engineers use application output more effectively Organizing a software security team before youve even created requirements Avoiding the unmanageable complexity and inherent flaws of layered security Implementing positive software design practices and identifying security defects in existing designs Teaming to improve code reviews, clarify attack scenarios associated with vulnerable code, and validate positive compliance Moving beyond pentesting toward more comprehensive security testing Integrating your new application with your existing security infrastructure Ruggedizing DevOps by adding infosec to the relationship between development and operations Protecting application security during maintenance

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

STRENGTHEN SOFTWARE SECURITY BY HELPING DEVELOPERS AND SECURITY EXPERTS WORK TOGETHER Traditional approaches to securing software are inadequate. The solution: Bring software engineering and network security teams together in a new, holistic approach to protecting the entire enterprise. Now, four highly respected security experts explain why this confluence is so crucial, and show how to implement it in your organization. Writing for all software and security practitioners and leaders, they show how software can play a vital, active role in protecting your organization. Youll learn how to construct software that actively safeguards sensitive data and business processes and contributes to intrusion detection/response in sophisticated new ways. The authors cover the entire development lifecycle, including project inception, design, implementation, testing, deployment, operation, and maintenance. They also provide a full chapter of advice specifically for Chief Information Security Officers and other enterprise security executives. Whatever your software security responsibilities, Enterprise Software Security delivers indispensable big-picture guidanceand specific, high-value recommendations you can apply right now. COVERAGE INCLUDES: Overcoming common obstacles to collaboration between developers and IT security professionals Helping programmers design, write, deploy, and operate more secure software Helping network security engineers use application output more effectively Organizing a software security team before youve even created requirements Avoiding the unmanageable complexity and inherent flaws of layered security Implementing positive software design practices and identifying security defects in existing designs Teaming to improve code reviews, clarify attack scenarios associated with vulnerable code, and validate positive compliance Moving beyond pentesting toward more comprehensive security testing Integrating your new application with your existing security infrastructure Ruggedizing DevOps by adding infosec to the relationship between development and operations Protecting application security during maintenance

Key concepts: Software security assurance, Security engineering, Computer science, Security information and event management, Security testing, Computer security, Software development, Software deployment

Related papers

Back to paper searchBrowse research topicsOriginal source
Enterprise Software Security: A Confluence of Disciplines — Research Paper | ScholarLens