[Owasp-leaders] The Rocky Road To More Secure Code
aj.dexter at gmail.com
aj.dexter at gmail.com
Thu Apr 9 20:17:16 EDT 2009
Tom,
Agree with all points. Except to RACF. I'm still lucky enough to be in an environment using it, and its not as cool as it might seem.
AJ Dexter
Portland Chapter
-----Original Message-----
From: "Tom Brennan - OWASP" <tomb at owasp.org>
Date: Fri, 10 Apr 2009 00:08:13
To: Owasp-Leaders at Lists.Owasp<owasp-leaders at lists.owasp.org>
Subject: Re: [Owasp-leaders] The Rocky Road To More Secure Code
(Netcraft) 1M websites running SSL so they are protecting something..., if only 50% were "really important" that's a lot of code... Its also a lot of"levels" of security (loss of life, production, etc)
This snap shot of course does not count new sites coming online every day.
So approaching the insecure running code issue from a business perspective the business wants to know what is the risk today. After black box options include accept the risk(waiver), shut off the site or use a compensating control
Issues identified on existing sites in the public facing world today, can then be tied back to improving "process" for future applications developed and deployed including education, source, design, qa and architecture (not in the right order btw)
Technical
- Confidentiality
- Integrity
- Availability
Business
- Financial Damage
- Non-compliance
- Privacy violation
- Reputation damage
OWASP has the resources for business/gov that's step #1. We have some books, studies, tools and both drop in solutions ESAPI/OWASP ModSec Project just to name a few of MANY...
For those with decades of insight, how many times have we witnessed the business politics disrupt a solid CISO/CIO strategy. Its not black and white world... rather "shades of gray" and changing behavior and raising awareness and options is our mission @ owasp, we're doing it - 10 years ago the media did not care.... Nor did business "the rulz have changed". Let's get the 70% of the Top 100 websites to pay attention... as they have hosted malware at one time.
Sometimes I miss RACF and 8-bit Atari's :)
-----Original Message-----
From: "Marco M. Morana" <marco.m.morana at gmail.com>
Date: Thu, 9 Apr 2009 19:25:30
To: <owasp-leaders at lists.owasp.org>
Subject: [Owasp-leaders] The Rocky Road To More Secure Code
_______________________________________________
OWASP-Leaders mailing list
OWASP-Leaders at lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-leaders
_______________________________________________
OWASP-Leaders mailing list
OWASP-Leaders at lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-leaders
More information about the OWASP-Leaders
mailing list