DocumentCode
1180470
Title
Bridging the gap between software development and information security
Author
Wyk, Kenneth R Van ; McGraw, Gary
Author_Institution
Cigital, Dulles, VA, USA
Volume
3
Issue
5
fYear
2005
Firstpage
75
Lastpage
79
Abstract
Traditionally, software development efforts in large corporations have been about as far removed from information security as they were from human resources or any other business function. Software development has also had the tendency to be highly distributed among business units and thus not even practiced in a cohesive, coherent manner. In the worst cases, busy business unit executives trade roving bands of developers like Pokemon cards in a fifth-grade classroom (in an attempt to get ahead). Suffice it to say, none of this is good. The disconnect between security and development has ultimately produced software development efforts that lack any sort of contemporary understanding of technical security risks. Today´s complex and highly connected computing environments trigger myriad security concerns, so by blowing off the idea of security entirely, software builders virtually guarantee that their creations have way too many security weaknesses that could - and should - have been avoided. This article presents some recommendations for solving this problem. Our approach is born out of experience in two diverse fields: software security and information security. Central among our recommendations is the notion of using the knowledge inherent in information security organizations to enhance secure software development efforts.
Keywords
security of data; software engineering; information security; software development; software security; technical security risk; Best practices; Computer bugs; Costs; Humans; Information security; Programming; Risk analysis; Software design; Software testing; System testing; BSI; building security in; infosec; softdev;
fLanguage
English
Journal_Title
Security & Privacy, IEEE
Publisher
ieee
ISSN
1540-7993
Type
jour
DOI
10.1109/MSP.2005.118
Filename
1514408
Link To Document