• DocumentCode
    1455492
  • Title

    10 Quick, Dirty, and Cheap Things to Improve Enterprise Security

  • Author

    McGovern, James ; Peterson, Gunnar

  • Volume
    8
  • Issue
    2
  • fYear
    2010
  • Firstpage
    83
  • Lastpage
    85
  • Abstract
    As software security has increasingly become an important part of information security programs, there have been some notable trends and successes of various tools, processes, and models. Because "building security in" is so different from how enterprise software has historically been developed, the changes might seem revolutionary. In the enterprise, revolutionary changes involve cost and complexity, as organizations figure out how to incorporate new techniques, processes, and technology. The paper shows an informal list that doesn\´t say, "simply reboot your entire enterprise software development and you are ready to begin secure coding." Instead, it describes how people with limited budgets and/or authority can make potentially big changes in their enterprise software\´s overall security. 10 low or no-cost ideas were discussed in this paper.
  • Keywords
    security of data; enterprise security; enterprise software; organization process; organization rechnology; organization techniques; revolutionary changes; software development; software security; Costs; Information security; Programming; Software tools; audit logging; enterprise software; security and privacy; software development; software security; threat modeling;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2010.61
  • Filename
    5439536