Scaling a Software Security Initiative: Lessons from the BSIMM

Learn important lessons in scaling software security touchpoints, and making them work efficiently and effectively in a global software security initiative. Gary McGraw, CTO at Cigital, focuses on the top three touchpoints?code review with a static analysis tool, architectural risk analysis, and penetration testing?discussing the tools, technologies, people, and processes for each. He addresses the issues head on, using examples from the 70+ Building Security in Maturity Model (BSIMM) firms and many years of real-world experience. (Firms in the BSIMM include Adobe, Aon, Bank of America, Box, Capital One, , EMC, Fannie Mae, Fidelity, Google, Intel, Intuit, JPMorgan Chase & Co., Microsoft, Nokia Siemens Networks, Qualcomm, Rackspace, Salesforce, Sallie Mae, SAP, Sony Mobile, Symantec, Telecom Italia, Thomson Reuters, Visa, VMware, and Wells Fargo.)
  • IEEE MemberUS $49.00
  • Society MemberUS $49.00
  • IEEE Student MemberUS $49.00
  • Non-IEEE MemberUS $49.00
Purchase

Videos in this product

Scaling a Software Security Initiative: Lessons from the BSIMM

00:51:33
0 views
Learn important lessons in scaling software security touchpoints, and making them work efficiently and effectively in a global software security initiative. Gary McGraw, CTO at Cigital, focuses on the top three touchpoints?code review with a static analysis tool, architectural risk analysis, and penetration testing?discussing the tools, technologies, people, and processes for each. He addresses the issues head on, using examples from the 70+ Building Security in Maturity Model (BSIMM) firms and many years of real-world experience. (Firms in the BSIMM include Adobe, Aon, Bank of America, Box, Capital One, , EMC, Fannie Mae, Fidelity, Google, Intel, Intuit, JPMorgan Chase & Co., Microsoft, Nokia Siemens Networks, Qualcomm, Rackspace, Salesforce, Sallie Mae, SAP, Sony Mobile, Symantec, Telecom Italia, Thomson Reuters, Visa, VMware, and Wells Fargo.)